PT-2024-7106 · Linux+3 · Linux Kernel+3

Ignat Korchagin

·

Published

2021-12-20

·

Updated

2024-11-07

·

CVE-2021-47094

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the KVM (Kernel-based Virtual Machine) component of the Linux kernel, specifically with the x86/mmu (Memory Management Unit) module. The problem arises when the iterator is advanced after a restart due to yielding, which can cause the top-level SPTE (Shadow Page Table Entry) and its children to be skipped. This can lead to a use-after-free condition, resulting in data corruption and additional errors in the kernel. The vulnerability can be exploited by an attacker to potentially elevate their privileges in the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08378
CVE-2021-47094
OESA-2024-1353
OESA-2024-1355
OESA-2024-1356
OESA-2024-1357
OPENSUSE-SU-2024_1321-1
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1490-1
SUSE-SU-2024:1320-1
SUSE-SU-2024:1321-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1490-1

Affected Products

Debian
Linux Kernel
Red Os
Suse