Back to search
CVE-2021-22543
Published: May 26, 2021
Modified: Sep 16, 2024
PUBLISHED
Description
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.
| Vendor | Product | Versions |
|---|---|---|
Linux Kernel | Linux Kernel | affected add6a0cd1c5ba51b201e1361b05a5df817083618 - < f8be156be163a052a067306417cd0ff679068c97 |
Weaknesses (CWE)
References
[oss-security] 20210626 Re: CVE-2021-22543 - /dev/kvm LPE
mailing-list
x_refsource_MLIST
FEDORA-2021-fe826f202e
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-95f2f1cfc7
vendor-advisory
x_refsource_FEDORA
https://security.netapp.com/advisory/ntap-20210708-0002/
x_refsource_CONFIRM
[debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20211216 [SECURITY] [DLA 2843-1] linux security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now