VDB
BDU%3A2021-04883
BDU%3A2021-04883
PUBLISHED
CVSS 6.900000095367432 MEDIUM
Уязвимость компонента arch/x86/kvm/svm/nested.c операционной системы Linux , связанная с использованием памяти после её освобождения, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 2.0
6.900000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Red Hat Inc., Canonical Ltd., АО "НППКТ" | Debian GNU/Linux, Red Hat Enterprise Linux, Ubuntu, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), Linux |
Timeline
- Oct 5, 2021 CVE Published
- Sep 13, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
References
- http://packetstormsecurity.com/files/163324/KVM-nested_svm_vmrun-Double-Fetch.html url
- https://bugs.chromium.org/p/project-zero/issues/detail?id=2177 url
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.12 url
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29657 url
- https://git.kernel.org/linus/a58d9166a756a0f4a6618e4f593232593d6df134 url
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a58d9166a756a0f4a6618e4f593232593d6df134 url
- https://googleprojectzero.blogspot.com/2021/06/an-epyc-escape-case-study-of-kvm.html url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.28 url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.12 url
- https://security.netapp.com/advisory/ntap-20210902-0008/ url
- https://ubuntu.com/security/notices/USN-4948-1 url
- https://usn.ubuntu.com/usn/usn-4948-1 url
- https://www.cve.org/CVERecord?id=CVE-2021-29657 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.4/ url
- https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-29657.xml advisory
- https://ubuntu.com/security/CVE-2021-29657 advisory
- https://security-tracker.debian.org/tracker/CVE-2021-29657 advisory