kernel: userspace applications can misuse the KVM API to cause a write of 16 bytes at an offset up to 32 GB from vcpu->run
Published May 5, 2021
7.8
HIGHCVSS 3.1
EPSS 0.38%
Description
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
Affected products
-
Affected
- ≥ 5.11, < 5.11.16
- ≥ 5.9, < 5.10.32
Configuration 1
- < 5.12
Configuration 2
- 8.0
- 8
- 8
- 8.4
- 8.4
Configuration 3
- 33
Configuration 4
- 4.0
- 4.0
Running on/with
- 8.0
Configuration 5
- n/a
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-305.3.1.el8_4
Fixed · RHSA-2021:2168
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-305.3.1.rt7.75.el8_4
Fixed · RHSA-2021:2169
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2021:2165
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.4.6-20210615.0.el8_4
Fixed · RHSA-2021:2522
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-305.3.1.el8_4 | Fixed | RHSA-2021:2168 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-305.3.1.rt7.75.el8_4 | Fixed | RHSA-2021:2169 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2021:2165 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.4.6-20210615.0.el8_4 | Fixed | RHSA-2021:2522 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affected Linux kernel versions as shipped with Red Hat Enterprise Linux 8 starting with RHEL-8.4.0 and onward kernel version.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
References (7)
- https://access.redhat.com/security/cve/CVE-2021-3501 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1950136 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26821 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04c4f2ee3f68c9a4bf1653d15f1a9a435ae33f7a x_refsource_MISCMailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3501
- https://security.netapp.com/advisory/ntap-20210618-0008/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3501
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-3501 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1950136 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26821 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04c4f2ee3f68c9a4bf1653d15f1a9a435ae33f7a | x_refsource_MISCMailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-3501 | ||
| https://security.netapp.com/advisory/ntap-20210618-0008/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2021-3501 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data