Vulnerability Name: | CVE-2021-4095 (CCN-215265) | ||||||||||||
Assigned: | 2021-12-14 | ||||||||||||
Published: | 2021-12-14 | ||||||||||||
Updated: | 2022-07-28 | ||||||||||||
Summary: | A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a denial of service by issuing a KVM_XEN_HVM_SET_ATTR ioctl. This flaw affects Linux kernel versions prior to 5.17-rc1. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-476 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-4095 Source: MLIST Type: Exploit, Mailing List, Patch, Third Party Advisory [oss-security] 20220117 Re: CVE-2021-4095: kernel: KVM: NULL pointer dereference in kvm_dirty_ring_get() in virt/kvm/dirty_ring.c Source: MISC Type: Exploit, Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2031194 Source: XF Type: UNKNOWN linux-kernel-cve20214095-dos(215265) Source: CCN Type: Linux Kernel GIT Repository KVM: x86: Fix wall clock writes in Xen shared_info not to mark page dirty Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-0816754490 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-8efcea6e67 Source: CCN Type: oss-sec Mailing List, Tue, 14 Dec 2021 23:26:10 +0800 CVE-2021-4095: kernel: KVM: NULL pointer dereference in kvm_dirty_ring_get() in virt/kvm/dirty_ring.c Source: CCN Type: oss-sec Mailing List, Mon, 17 Jan 2022 12:33:54 +0800 Re: CVE-2021-4095: kernel: KVM: NULL pointer dereference in kvm_dirty_ring_get() in virt/kvm/dirty_ring.c Source: CCN Type: Linux Kernel Web site The Linux Kernel Archives | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
BACK |