Back

HIGH

kernel: userspace applications can misuse the KVM API to cause a write of 16 bytes at an offset up to 32 GB from vcpu->run

Published May 5, 2021

Description

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.

Affected products

Remediation

Red Hat statement

This issue affected Linux kernel versions as shipped with Red Hat Enterprise Linux 8 starting with RHEL-8.4.0 and onward kernel version.

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published May 5, 2021
Updated Aug 5, 2026
Reserved Apr 15, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Aug 5, 2026

Red Hat

Severity Important
Public date Apr 13, 2021
Bugzilla 1950136

ENISA EUVD

Assigner redhat
Published May 5, 2021
Updated Aug 5, 2026

GitHub

No data