LSN-0081-1
Vulnerability Summary
Timeline
Description
Kernel Live Patch Security Notice Maxim Levitsky discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel did not properly prevent a guest VM from enabling AVIC in nested guest VMs. An attacker in a guest VM could use this to write to portions of the host's physical memory.(CVE-2021-3653) Maxim Levitsky and Paolo Bonzini discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel allowed a guest VM to disable restrictions on VMLOAD/VMSAVE in a nested guest. An attacker in a guest VM could use this to read or write portions of the host's physical memory.(CVE-2021-3656) Andy Nguyen discovered that the netfilter subsystem in the Linux kernel contained an out-of-bounds write in its setsockopt() implementation. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2021-22555) It was discovered that the virtual file system implementation in the Linux kernel contained an unsigned to signed integer conversion error. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.(CVE-2021-33909)
Affected Systems
- ubuntu•linux
all | < 4.4.0-214.246 | < 4.15.0-156.163 | < 5.4.0-84.94
- ubuntu•linux-gcp
all | < 5.4.0-1052.56
- ubuntu•linux-gke
all | < 5.4.0-1052.55
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.4
all | < 5.4.0-1052.55~18.04.1
- ubuntu•linux-gkeop
all | < 5.4.0-1023.24
- ubuntu•linux-gkeop-5.4
all | < 5.4.0-1023.24~18.04.1
- ubuntu•linux-hwe
all | < 4.15.0-156.163~16.04.1
- ubuntu•linux-hwe-5.4
all | < 5.4.0-84.94~18.04.1
- ubuntu•linux-lts-xenial
all | < 4.4.0-214.246~14.04.1
- ubuntu•linux-oem
all