CVE-2021-22543

Aliases:RHSA-2021:3943RHSA-2022:5640UBUNTU-CVE-2021-22543DEBIAN-CVE-2021-22543
Advisory lineage Upstream: 0 Downstream: 53
Modified
Published: 26 May 2021, 10:30
Last modified:16 Sept 2024, 23:26

Vulnerability Summary

Overall Risk (default)
medium
45/100
CVSS Score
8.7 HIGH
v4.0 (cve.org)
EPSS Score
0.66% LOW
1% probability +0.66%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

26 May 2021, 10:30
Published
Vulnerability first disclosed
16 Sept 2024, 23:26
Last Modified
Vulnerability information updated

Description

An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
  • v4.0HIGHScore: 8.7CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v3.1HIGHScore: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 4.6AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.66% Percentile: 50%

Techniques & Countermeasures

  • CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer

    The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Affected Systems

  • debianlinux

    < 5.10.46-2 | < 5.10.46-2 | < 5.10.46-2 | < 5.10.46-2

  • ubuntulinux

    < 4.15.0-159.167 | < 5.4.0-84.94

  • ubuntulinux-aws

    < 4.15.0-1112.119 | < 5.4.0-1056.59

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    < 5.11.0-1017.18~20.04.1

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1056.59~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-fips

    < 4.15.0-2054.56 | all | < 5.4.0-1069.73+fips2

  • ubuntulinux-aws-hwe

    < 4.15.0-1112.119~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1124.137~14.04.1 | < 4.15.0-1124.137~16.04.1 | all | < 5.4.0-1058.60

  • ubuntulinux-azure-4.15

    < 4.15.0-1124.137

  • ubuntulinux-azure-5.11

    < 5.11.0-1015.16~20.04.1

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1058.60~18.04.1

  • ubuntulinux-azure-5.8

    < 5.8.0-1043.46~20.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2036.40 | all | < 5.4.0-1073.76+fips1

  • ubuntulinux-bluefield

    all | < 5.4.0-1019.22

  • ubuntulinux-dell300x

    < 4.15.0-1028.33

  • ubuntulinux-fips

    < 4.15.0-1070.79 | all | < 5.4.0-1033.38

  • ubuntulinux-gcp

    < 4.15.0-1109.123~16.04.1 | all | < 5.4.0-1052.56

  • ubuntulinux-gcp-4.15

    < 4.15.0-1109.123

  • ubuntulinux-gcp-5.11

    < 5.11.0-1018.20~20.04.2

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1052.56~18.04.1

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-edge

    all

  • ubuntulinux-gcp-fips

    < 4.15.0-2019.21 | all | < 5.4.0-1067.71~20.04.1

  • ubuntulinux-gke

    < 5.4.0-1052.55

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.4

    < 5.4.0-1052.55~18.04.1

  • ubuntulinux-gkeop

    < 5.4.0-1023.24

  • ubuntulinux-gkeop-5.4

    < 5.4.0-1023.24~18.04.1

  • ubuntulinux-hwe

    < 4.15.0-159.167~16.04.1 | all

  • ubuntulinux-hwe-5.11

    < 5.11.0-34.36~20.04.1

  • ubuntulinux-hwe-5.4

    < 5.4.0-84.94~18.04.1

  • ubuntulinux-hwe-5.8

    all

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    < 4.15.0-1100.102 | < 5.4.0-1046.48

  • ubuntulinux-oem

    all

  • ubuntulinux-oem-5.10

    < 5.10.0-1049.51

  • ubuntulinux-oem-5.6

    all

  • ubuntulinux-oracle

    < 4.15.0-1081.89~16.04.1 | < 4.15.0-1081.89 | < 5.4.0-1054.58

  • ubuntulinux-oracle-5.0

    all

  • ubuntulinux-oracle-5.11

    < 5.11.0-1017.18~20.04.1

  • ubuntulinux-oracle-5.3

    all

  • ubuntulinux-oracle-5.4

    < 5.4.0-1054.58~18.04.1

Showing first 50 affected entries in server-rendered view.

References (32)