VDB

CVE-2021-29657

CVE-2021-29657 PUBLISHED

arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass access control on host OS MSRs when there are nested guests, aka CID-a58d9166a756. This occurs because of a TOCTOU race condition associated with a VMCB12 double fetch in nested_svm_vmrun.

EPSS 0.05% · 15.0th percentile

Risk Scores

EPSS Score
0.05%
15.0th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-oracle-5.3*, 0, 5.3.0-1030.32~18.04.1
Ubuntu:18.04:LTSlinux-azure4.15.0-1021.21, 4.15.0-1018.18, 4.15.0-1014.14
Ubuntu:16.04:LTSlinux-hwe-edge4.13.0-21.24~16.04.1, 4.13.0-19.22~16.04.1, 4.13.0-17.20~16.04.1
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1069.72, 4.15.0-1064.67, 4.15.0-1063.66
Ubuntu:18.04:LTSlinux-azure-edge*, *, 5.0.0-1012.12~18.04.2
Ubuntu:18.04:LTSlinux-hwe-edge*, *, *
Ubuntu:18.04:LTSlinux-gcp4.15.0-1003.3, 4.15.0-1005.5, 4.15.0-1006.6
Ubuntu:18.04:LTSlinux-azure-5.3*, *, *
Ubuntu:18.04:LTSlinux-gcp-5.3*, 0, 5.3.0-1008.9~18.04.1
Ubuntu:18.04:LTSlinux-aws-5.35.3.0-1034.36, *, *
Ubuntu:18.04:LTSlinux-oracle-5.05.0.0-1010.15~18.04.1, 5.0.0-1008.13~18.04.1, 5.0.0-1009.14~18.04.1
Ubuntu:20.04:LTSlinux-riscv5.4.0-31.35, 5.4.0-36.41, 5.4.0-37.42
Ubuntu:20.04:LTSlinux-oem-5.105.10.0-1019.20, 5.10.0-1021.22, 5.10.0-1023.24
Ubuntu:18.04:LTSlinux-oem4.15.0-1094.104, 0, 4.15.0-1073.83
Ubuntu:18.04:LTSlinux-aws-5.05.0.0-1027.30, 5.0.0-1025.28, 5.0.0-1024.27~18.04.1
Ubuntu:18.04:LTSlinux-gcp-edge4.18.0-1013.14~18.04.1, 4.18.0-1015.16~18.04.1, 5.0.0-1013.13~18.04.1
Ubuntu:18.04:LTSlinux-hwe4.18.0-15.16~18.04.1, *, *
Ubuntu:20.04:LTSlinux-raspi25.3.0-1014.16, 5.3.0-1007.8, 5.4.0-1006.6

Timeline

  • Apr 3, 2021 CVE Published
  • Jul 23, 2021 EPSS Score
  • Sep 20, 2021 EPSS Score
  • Nov 19, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 17, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 16, 2022 EPSS Score
  • Jul 15, 2022 EPSS Score
  • Sep 12, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›