Описание
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.
A flaw was found in the Linux kernel, where it incorrectly computes the access permissions of a shadow page. This issue leads to a missing guest protection page fault.
Отчет
The issue is rated as having Low impact because the issue is not present when hardware-assisted paging (also known as nested paging and Second Level Address Translation) is enabled. Hardware-assisted paging is enabled by default for CPUs that support it. Any realistic real-life virtualization scenario benefits greatly from hardware assisted paging speed up, so deployments without hardware-assisted paging are very rare.
Меры по смягчению последствий
Do not disable hardware-assisted paging (also known as nested paging and Second Level Address Translation) on your hosts. The default is on.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | kernel | Out of support scope | ||
Red Hat Enterprise Linux 7 | kernel | Fix deferred | ||
Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | ||
Red Hat Enterprise Linux 8 | kernel | Affected | ||
Red Hat Enterprise Linux 8 | kernel-rt | Affected | ||
Red Hat Enterprise Linux 9 | kernel | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS3
Связанные уязвимости
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 inco ...
arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shadow page, leading to a missing guest protection page fault.
Уязвимость ядра операционной системы Linux , связанная с недостаточной проверкой присвоения разрешений для критичного ресурса, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.4 Medium
CVSS3