CVE-2021-37576

Aliases:RHSA-2021:3436UBUNTU-CVE-2021-37576DEBIAN-CVE-2021-37576
Modified
Published: 26 Jul 2021, 21:35
Last modified:04 Aug 2024, 01:23

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.57% LOW
1% probability +0.56%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

26 Jul 2021, 21:35
Published
Vulnerability first disclosed
04 Aug 2024, 01:23
Last Modified
Vulnerability information updated

Description

arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.57% Percentile: 46%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • debianlinux

    < 5.10.46-5 | < 5.14.6-1 | < 5.14.6-1 | < 5.14.6-1

  • ubuntulinux

    all | < 4.15.0-159.167 | < 5.4.0-88.99

  • ubuntulinux-aws-fips

    < 4.15.0-2054.56 | all | < 5.4.0-1069.73+fips2

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2036.40 | all | < 5.4.0-1073.76+fips1

  • ubuntulinux-bluefield

    all

  • ubuntulinux-dell300x

    < 4.15.0-1028.33

  • ubuntulinux-fips

    all | < 4.15.0-1070.79 | < 5.4.0-1034.40

  • ubuntulinux-gcp-5.11

    < 5.11.0-1020.22~20.04.1

  • ubuntulinux-gcp-fips

    < 4.15.0-2019.21 | all | < 5.4.0-1067.71~20.04.1

  • ubuntulinux-hwe

    < 4.15.0-159.167~16.04.1 | all

  • ubuntulinux-hwe-5.11

    < 5.11.0-37.41~20.04.2

  • ubuntulinux-hwe-5.4

    < 5.4.0-87.98~18.04.1

  • ubuntulinux-hwe-5.8

    all

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-ibm

    < 5.4.0-1005.6

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-lts-xenial

    all

  • ubuntulinux-raspi-realtime

    all

  • ubuntulinux-realtime

    all

  • fedoraprojectfedora

    33 | 34

  • linuxlinux_kernel

    ≥ 3.10, < 4.4.277 | ≥ 4.5, < 4.9.277 | ≥ 4.10, < 4.14.241 | ≥ 4.15, < 4.19.199 | ≥ 4.20, < 5.4.136 | ≥ 5.5, < 5.10.54 | ≥ 5.11, < 5.13.6

  • redhatkpatch-patch-4_18_0-305

    < 0:1-5.el8

  • redhatkpatch-patch-4_18_0-305_10_2

    < 0:1-2.el8_4

  • redhatkpatch-patch-4_18_0-305_10_2-debuginfo

    < 0:1-2.el8_4

  • redhatkpatch-patch-4_18_0-305_10_2-debugsource

    < 0:1-2.el8_4

  • redhatkpatch-patch-4_18_0-305_12_1

    < 0:1-1.el8_4

  • redhatkpatch-patch-4_18_0-305_12_1-debuginfo

    < 0:1-1.el8_4

  • redhatkpatch-patch-4_18_0-305_12_1-debugsource

    < 0:1-1.el8_4

  • redhatkpatch-patch-4_18_0-305_3_1

    < 0:1-4.el8_4

  • redhatkpatch-patch-4_18_0-305_3_1-debuginfo

    < 0:1-4.el8_4

  • redhatkpatch-patch-4_18_0-305_3_1-debugsource

    < 0:1-4.el8_4

  • redhatkpatch-patch-4_18_0-305_7_1

    < 0:1-3.el8_4

  • redhatkpatch-patch-4_18_0-305_7_1-debuginfo

    < 0:1-3.el8_4

  • redhatkpatch-patch-4_18_0-305_7_1-debugsource

    < 0:1-3.el8_4

  • redhatkpatch-patch-4_18_0-305-debuginfo

    < 0:1-5.el8

  • redhatkpatch-patch-4_18_0-305-debugsource

    < 0:1-5.el8

References (23)