Fiche vulnérabilité
CVE-2021-22543 : faille élevée linux linux kernel (CVSS 7.8)
Description
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 26 mai 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- linux linux kernel
- fedoraproject fedora
- debian debian linux
- netapp h410c firmware
- netapp h300s firmware
- netapp h500s firmware
- netapp h700s firmware
- netapp h300e firmware
- netapp h500e firmware
- netapp h700e firmware
- netapp h410s firmware
- netapp cloud backup
- netapp solidfire baseboard management controller firmware
Références
- Fiche CVE-2021-22543 sur le NVD (NIST)
- openwall.com/lists/oss-security/2021/06/26/1
- github.com/google/security…
- lists.debian.org/debian-lts-announce/2021/10/msg00010.html
- lists.debian.org/debian-lts-announce/2021/12/msg00012.html
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- security.netapp.com/advisory/ntap-20210708-0002/