Aller au contenu

Fiche vulnérabilité

CVE-2021-22543 : faille élevée linux linux kernel (CVSS 7.8)

Description

An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 mai 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • linux linux kernel
  • fedoraproject fedora
  • debian debian linux
  • netapp h410c firmware
  • netapp h300s firmware
  • netapp h500s firmware
  • netapp h700s firmware
  • netapp h300e firmware
  • netapp h500e firmware
  • netapp h700e firmware
  • netapp h410s firmware
  • netapp cloud backup
  • netapp solidfire baseboard management controller firmware

Références

Rechercher une autre vulnérabilité dans la base CVE