7.1

CVE-2021-47255

kvm: LAPIC: Restore guard to prevent illegal APIC register access

In the Linux kernel, the following vulnerability has been resolved:

kvm: LAPIC: Restore guard to prevent illegal APIC register access

Per the SDM, "any access that touches bytes 4 through 15 of an APIC
register may cause undefined behavior and must not be executed."
Worse, such an access in kvm_lapic_reg_read can result in a leak of
kernel stack contents. Prior to commit 01402cf81051 ("kvm: LAPIC:
write down valid APIC registers"), such an access was explicitly
disallowed. Restore the guard that was removed in that commit.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.3 < 5.4.128
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.46
Linux ≫ Linux Kernel Version >= 5.11 < 5.12.13
Linux ≫ Linux Kernel Version 5.13 Update rc1
Linux ≫ Linux Kernel Version 5.13 Update rc2
Linux ≫ Linux Kernel Version 5.13 Update rc3
Linux ≫ Linux Kernel Version 5.13 Update rc4
Linux ≫ Linux Kernel Version 5.13 Update rc5
Linux ≫ Linux Kernel Version 5.13 Update rc6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.153
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/018685461a5b9a9a70e664ac77aef0d7415a3fd5
Patch
https://git.kernel.org/stable/c/218bf772bddd221489c38dde6ef8e917131161f6
Patch
https://git.kernel.org/stable/c/a2aff09807fbe4018c269d3773a629949058b210
Patch
https://git.kernel.org/stable/c/bf99ea52970caeb4583bdba1192c1f9b53b12c84
Patch