Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-22543

Опубликовано: 26 мая 2021
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.10.46-2package
linuxfixed4.19.208-1busterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2021/05/26/3

  • https://github.com/google/security-research/security/advisories/GHSA-7wq5-phmq-m584

  • https://git.kernel.org/linus/f8be156be163a052a067306417cd0ff679068c97

EPSS

Процентиль: 0%
0.00006
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

CVSS3: 7
redhat
около 4 лет назад

An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

CVSS3: 7.8
nvd
около 4 лет назад

An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

CVSS3: 7.8
fstec
около 4 лет назад

Уязвимость операционной системы Linux вызвана переполнением буфера, позволяющая нарушителю выполнить произвольную команду управления

suse-cvrf
почти 4 года назад

Security update for the Linux Kernel (Live Patch 17 for SLE 15 SP2)

EPSS

Процентиль: 0%
0.00006
Низкий