Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-47639

Опубликовано: 26 фев. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Zap all roots when unmapping gfn range in TDP MMU Zap both valid and invalid roots when zapping/unmapping a gfn range, as KVM must ensure it holds no references to the freed page after returning from the unmap operation. Most notably, the TDP MMU doesn't zap invalid roots in mmu_notifier callbacks. This leads to use-after-free and other issues if the mmu_notifier runs to completion while an invalid root zapper yields as KVM fails to honor the requirement that there must be no references to the page after the mmu_notifier returns. The bug is most easily reproduced by hacking KVM to cause a collision between set_nx_huge_pages() and kvm_mmu_notifier_release(), but the bug exists between kvm_mmu_notifier_invalidate_range_start() and memslot updates as well. Invalidating a root ensures pages aren't accessible by the guest, and KVM won't read or write page data itself, but KVM will trigger e.g. kvm...

РелизСтатусПримечание
bionic

not-affected

4.13.0-16.19
devel

not-affected

6.11.0-8.8
esm-infra-legacy/trusty

not-affected

3.13.0-173.224
esm-infra/bionic

not-affected

4.13.0-16.19
esm-infra/focal

not-affected

5.4.0-9.12
esm-infra/xenial

not-affected

4.4.0-2.16
focal

not-affected

5.4.0-9.12
jammy

released

5.15.0-37.39
noble

not-affected

6.5.0-9.9
oracular

not-affected

6.8.0-31.31

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

end of kernel support
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1001.1
devel

not-affected

6.11.0-1004.4
esm-infra-legacy/trusty

not-affected

4.4.0-1054.58
esm-infra/bionic

not-affected

4.15.0-1001.1
esm-infra/focal

not-affected

5.4.0-1005.5
esm-infra/xenial

not-affected

4.4.0-1001.10
focal

not-affected

5.4.0-1005.5
jammy

released

5.15.0-1011.14
noble

not-affected

6.5.0-1008.8
oracular

not-affected

6.8.0-1008.8

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-aws-5.3
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-aws-5.13
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-aws-5.13]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-aws-5.15
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-aws-5.15]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1015.19~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1015.19~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-aws-6.2
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-aws-5.4
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

5.4.0-1020.20~18.04.2
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1020.20~18.04.2
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-aws-5.11
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-aws-5.11]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-aws-6.5
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-aws-6.8
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1009.9~22.04.2
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

fips-preview/jammy

not-affected

5.15.0-1051.56+fips1
fips-updates/bionic

not-affected

4.15.0-2000.4
fips-updates/focal

not-affected

5.4.0-1021.21+fips2
fips-updates/jammy

not-affected

5.15.0-1052.57+fips1
fips-updates/xenial

DNE

fips/bionic

not-affected

4.15.0-2000.4

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

not-affected

4.15.0-1031.33~16.04.1
focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

6.11.0-1004.4
esm-infra-legacy/trusty

not-affected

4.15.0-1059.64~14.04.1
esm-infra/bionic

ignored

superseded by linux-azure-5.3
esm-infra/focal

not-affected

5.4.0-1006.6
esm-infra/xenial

not-affected

4.11.0-1015.15
focal

not-affected

5.4.0-1006.6
jammy

released

5.15.0-1010.12
noble

not-affected

6.5.0-1007.7
oracular

not-affected

6.8.0-1007.7

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1082.92
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1082.92
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-azure-5.13
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-azure-5.13]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-azure-5.15
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-azure-5.15]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1008.9~20.04.1
esm-infra/xenial

DNE

focal

released

5.15.0-1008.9~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-azure-6.2
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-azure-5.4
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

5.4.0-1022.22~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1022.22~18.04.1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-azure-5.11
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-azure-5.11]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-azure-6.5
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-azure-6.8
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1008.8~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-azure-5.3
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-azure-fde-5.15
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-azure-fde-5.15]
jammy

not-affected

5.15.0-1019.24.1
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1019.24~20.04.1.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1019.24~20.04.1.1
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-azure-fde-6.2
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

replaced by linux-azure-6.5
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

fips-preview/jammy

not-affected

5.15.0-1053.61+fips1
fips-updates/bionic

not-affected

4.15.0-1002.2
fips-updates/focal

not-affected

5.4.0-1022.22+fips1
fips-updates/jammy

not-affected

5.15.0-1058.66+fips1
fips-updates/xenial

DNE

fips/bionic

not-affected

4.15.0-1002.2

Показывать по

РелизСтатусПримечание
bionic

DNE

bluefield/jammy

not-affected

5.15.0-1011.13
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1011.14
esm-infra/xenial

DNE

focal

not-affected

5.4.0-1011.14
jammy

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

fips-preview/jammy

not-affected

5.15.0-73.80+fips1
fips-updates/bionic

not-affected

4.15.0-1027.32
fips-updates/focal

not-affected

5.4.0-1026.30
fips-updates/jammy

not-affected

5.15.0-92.102+fips1
fips-updates/xenial

not-affected

4.4.0-1003.3
fips/bionic

not-affected

4.15.0-1011.12

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

6.11.0-1003.3
esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-gcp-5.3
esm-infra/focal

not-affected

5.4.0-1005.5
esm-infra/xenial

not-affected

4.10.0-1004.4
focal

not-affected

5.4.0-1005.5
jammy

released

5.15.0-1008.12
noble

not-affected

6.5.0-1007.7
oracular

not-affected

6.8.0-1007.7

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1071.81
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1071.81
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-gcp-5.13
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-gcp-5.13]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-gcp-5.15
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-gcp-5.15]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1006.9~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1006.9~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-gcp-6.2
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-gcp-5.4
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

5.4.0-1021.21~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1021.21~18.04.1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-gcp-5.11
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-gcp-5.11]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-gcp-6.5
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-gcp-6.8
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1010.11~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

fips-preview/jammy

not-affected

5.15.0-1048.56+fips1
fips-updates/bionic

not-affected

4.15.0-2013.14
fips-updates/focal

not-affected

5.4.0-1021.21+fips1
fips-updates/jammy

not-affected

5.15.0-1048.56+fips1
fips-updates/xenial

DNE

fips/bionic

not-affected

4.15.0-1001.1

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

end of kernel support
focal

ignored

end of kernel support
jammy

released

5.15.0-1008.10
noble

not-affected

6.8.0-1003.5
oracular

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-gke-5.0
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

end of kernel support
esm-infra/xenial

DNE

focal

ignored

end of kernel support
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

end of kernel support
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

end of kernel support
focal

ignored

end of kernel support
jammy

not-affected

5.15.0-1001.2
noble

not-affected

6.8.0-1001.3
oracular

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

ignored

end of kernel support
esm-infra/xenial

DNE

focal

ignored

end of kernel support
jammy

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

end of kernel support
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

replaced by linux-hwe-5.4
esm-infra/focal

DNE

esm-infra/xenial

not-affected

4.8.0-39.42~16.04.1
focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-hwe-5.13
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-hwe-5.13]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-hwe-5.15
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-hwe-5.15]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-41.44~20.04.1
esm-infra/xenial

DNE

focal

released

5.15.0-41.44~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-hwe-6.2
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

5.4.0-37.41~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-37.41~18.04.1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-hwe-5.11
focal

ignored

end of standard support, was ignored [superseded by linux-hwe-5.11]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.11.0-19.19~24.04.1
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-hwe-6.5
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-hwe-6.8
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-38.38~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-hwe-5.4
esm-infra/focal

DNE

esm-infra/xenial

ignored

superseded by linux-hwe
focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1004.5
esm-infra/xenial

DNE

focal

not-affected

5.4.0-1004.5
jammy

released

5.15.0-1007.8
noble

not-affected

6.5.0-1009.9
oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

not-affected

5.15.0-1034.37~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1034.37~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

5.4.0-1010.11~18.04.2
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1010.11~18.04.2
esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.8.0-1001.6
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

end of kernel support
focal

ignored

end of kernel support
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

ignored

superseded by Ubuntu Pro ppa version
noble

DNE

oracular

DNE

realtime/jammy

not-affected

5.15.0-1021.26
trusty

DNE

upstream

released

5.18~rc1, 5.15.33

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

released

5.15.0-1008.11
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1008.11~20.04.1
esm-infra/xenial

DNE

focal

released

5.15.0-1008.11~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1001.3
esm-infra/xenial

DNE

focal

not-affected

5.4.0-1001.3
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1002.2
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1002.2
esm-infra/focal

not-affected

5.4.0-1004.4
esm-infra/xenial

not-affected

4.4.0-1007.12
focal

not-affected

5.4.0-1004.4
jammy

released

5.15.0-1010.11
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

released

5.15.0-37.39
noble

not-affected

6.5.0-9.9.1
oracular

not-affected

6.8.0-31.31.1
trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-42.45~20.04.1
esm-infra/xenial

DNE

focal

released

5.15.0-42.45~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-lowlatency-hwe-6.2
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.11.0-1011.12~24.04.1
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-lowlatency-hwe-6.5
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-lowlatency-hwe-6.8
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-38.38.1~22.04.2
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

not-affected

4.4.0-164.192~14.04.1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

not-affected

4.4.0-13.29~14.04.1
trusty/esm

not-affected

4.4.0-13.29~14.04.1

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.15.0-1005.5
noble

not-affected

6.8.0-1007.7
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-nvidia-6.5
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-nvidia-6.8
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1008.8~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.8.0-1009.9.1
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.15.0-1013.13
noble

not-affected

6.8.0-1003.3
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

5.15.0-1001.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

replaced by linux-hwe-5.4
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-oem-5.13
focal

ignored

end of standard support, was ignored [superseded by linux-oem-5.13]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-oem-5.14
focal

ignored

end of standard support, was ignored [superseded by linux-oem-5.14]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

replaced by linux-hwe-5.15
focal

ignored

end of standard support, was ignored [replaced by linux-hwe-5.15]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-oem-6.1
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-oem-5.10
focal

ignored

end of standard support, was ignored [superseded by linux-oem-5.10]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-oem-6.1
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-oem-6.5
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.11.0-1007.7
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-oem-6.8
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

DNE

noble

not-affected

6.8.0-1003.3
oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1008.10
devel

not-affected

6.11.0-1006.6
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1008.10
esm-infra/focal

not-affected

5.4.0-1005.5
esm-infra/xenial

not-affected

4.15.0-1008.10~16.04.1
focal

not-affected

5.4.0-1005.5
jammy

released

5.15.0-1009.12
noble

not-affected

6.5.0-1010.10
oracular

not-affected

6.8.0-1005.5

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-oracle-5.3
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-oracle-5.13
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-oracle-5.13]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-oracle-5.15
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-oracle-5.15]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1007.9~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1007.9~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

ignored

superseded by linux-oracle-5.4
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

5.4.0-1021.21~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1021.21~18.04.1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-oracle-5.11
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-oracle-5.11]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-oracle-6.8
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-1006.6~22.04.3
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

6.11.0-1004.4
esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1007.7
focal

not-affected

5.4.0-1007.7
jammy

released

5.15.0-1011.13
noble

not-affected

6.5.0-1005.7
oracular

not-affected

6.8.0-1004.4
trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

5.4.0-1013.13~18.04.1
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.4.0-1013.13~18.04.1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

ignored

superseded by Ubuntu Pro ppa version
oracular

DNE

realtime/noble

not-affected

6.7.0-2001.1
trusty

DNE

upstream

released

5.18~rc1, 5.15.33

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

replaced by linux-raspi
focal

ignored

end of standard support, was ignored [replaced by linux-raspi]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

6.11.0-1001.1
esm-infra/focal

DNE

focal

DNE

jammy

ignored

superseded by Ubuntu Pro ppa version
noble

not-affected

6.8.1-1015.16
oracular

not-affected

6.11.0-1001.1
realtime/jammy

released

5.15.0-1014.14
realtime/noble

not-affected

6.8.0-1008.19
trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

not-affected

6.11.0-8.8.1
esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-riscv-5.8
focal

ignored

end of standard support, was ignored [superseded by linux-riscv-5.8]
jammy

ignored

end of kernel support
noble

not-affected

6.5.0-9.9.1
oracular

not-affected

6.8.0-31.31.1
trusty

DNE

trusty/esm

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-riscv-5.13
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-riscv-5.13]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.15.0-1015.17~20.04.1
esm-infra/xenial

DNE

focal

not-affected

5.15.0-1015.17~20.04.1
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

end of kernel support
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

ignored

superseded by linux-riscv-5.11
esm-infra/xenial

DNE

focal

ignored

end of standard support, was ignored [superseded by linux-riscv-5.11]
jammy

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-riscv-6.8
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

not-affected

6.8.0-38.38.1~22.04.1
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

end of kernel support
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

superseded by linux-starfive-6.5
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

DNE

focal

DNE

jammy

ignored

end of kernel support
noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

not-affected

5.4.0-1020.24
esm-infra/xenial

DNE

focal

not-affected

5.4.0-1020.24
jammy

not-affected

5.15.0-1022.26
noble

DNE

oracular

DNE

trusty

DNE

Показывать по

EPSS

Процентиль: 4%
0.00021
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU Zap both valid and invalid roots when zapping/unmapping a gfn range, as KVM must ensure it holds no references to the freed page after returning from the unmap operation. Most notably, the TDP MMU doesn't zap invalid roots in mmu_notifier callbacks. This leads to use-after-free and other issues if the mmu_notifier runs to completion while an invalid root zapper yields as KVM fails to honor the requirement that there must be _no_ references to the page after the mmu_notifier returns. The bug is most easily reproduced by hacking KVM to cause a collision between set_nx_huge_pages() and kvm_mmu_notifier_release(), but the bug exists between kvm_mmu_notifier_invalidate_range_start() and memslot updates as well. Invalidating a root ensures pages aren't accessible by the guest, and KVM won't read or write page data itself, but KVM will trigger e.g. kvm_se...

CVSS3: 7.8
nvd
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU Zap both valid and invalid roots when zapping/unmapping a gfn range, as KVM must ensure it holds no references to the freed page after returning from the unmap operation. Most notably, the TDP MMU doesn't zap invalid roots in mmu_notifier callbacks. This leads to use-after-free and other issues if the mmu_notifier runs to completion while an invalid root zapper yields as KVM fails to honor the requirement that there must be _no_ references to the page after the mmu_notifier returns. The bug is most easily reproduced by hacking KVM to cause a collision between set_nx_huge_pages() and kvm_mmu_notifier_release(), but the bug exists between kvm_mmu_notifier_invalidate_range_start() and memslot updates as well. Invalidating a root ensures pages aren't accessible by the guest, and KVM won't read or write page data itself, but KVM will trigger e.g. kvm_se

CVSS3: 7.8
debian
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: K ...

CVSS3: 7.8
github
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU Zap both valid and invalid roots when zapping/unmapping a gfn range, as KVM must ensure it holds no references to the freed page after returning from the unmap operation. Most notably, the TDP MMU doesn't zap invalid roots in mmu_notifier callbacks. This leads to use-after-free and other issues if the mmu_notifier runs to completion while an invalid root zapper yields as KVM fails to honor the requirement that there must be _no_ references to the page after the mmu_notifier returns. The bug is most easily reproduced by hacking KVM to cause a collision between set_nx_huge_pages() and kvm_mmu_notifier_release(), but the bug exists between kvm_mmu_notifier_invalidate_range_start() and memslot updates as well. Invalidating a root ensures pages aren't accessible by the guest, and KVM won't read or write page data itself, but KVM will trigger e.g. kvm...

CVSS3: 7.8
fstec
больше 3 лет назад

Уязвимость функции kvm_tdp_mmu_put_root() модуля arch/x86/kvm/mmu/tdp_mmu.c подсистемы виртуализации на платформе x86 ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 4%
0.00021
Низкий

7.8 High

CVSS3

Уязвимость CVE-2021-47639