PT-2024-11385 · Linux+2 · Linux Kernel+2
Mingwei Zhang
·
Published
2021-09-22
·
Updated
2024-07-11
·
CVE-2021-47389
CVSS v3.1
5.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.14.9
Description
The issue is related to a missing
sev decommission in sev receive start, which can result in subsequent SEV launch failures due to firmware memory leaks. According to AMD's SEV API, RECEIVE START generates a new guest context and needs to be paired with DECOMMISSION. The RECEIVE START command is the only command other than LAUNCH START that generates a new guest context and guest handle. Local network access enables an attack, but no exploit is yet available.Recommendations
To resolve the issue, upgrade the affected Linux kernel component to a version newer than 5.14.9. As a temporary workaround, consider restricting access to the
sev receive start function until a patch is available. Avoid using the RECEIVE START command without proper DECOMMISSION pairing to minimize the risk of exploitation.Fix
Missing Release of Resource after Effective Lifetime
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse