Lucene search

K
cveGitHub_MCVE-2021-32843
HistoryFeb 17, 2023 - 11:15 p.m.

CVE-2021-32843

2023-02-1723:15:11
CWE-476
GitHub_M
web.nvd.nist.gov
22
hyperkit
cve-2021-32843
hypervisor
virtio
denial of service

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

5.3

Confidence

High

EPSS

0

Percentile

13.2%

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, virtio.c has is a call to vc_cfgread that does not check for null which when called makes the host crash. This issue may lead to a guest crashing the host causing a denial of service. This issue is fixed in commit df0e46c7dbfd81a957d85e449ba41b52f6f7beb4.

Affected configurations

Nvd
Vulners
Node
mobyprojecthyperkitRange0.20210107
VendorProductVersionCPE
mobyprojecthyperkit*cpe:2.3:a:mobyproject:hyperkit:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "moby",
    "product": "hyperkit",
    "versions": [
      {
        "version": "0.20210107",
        "status": "affected",
        "lessThanOrEqual": "0.20210107",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

5.3

Confidence

High

EPSS

0

Percentile

13.2%

Related for CVE-2021-32843