Lucene search

K
cveGitHub_MCVE-2021-32844
HistoryFeb 17, 2023 - 11:15 p.m.

CVE-2021-32844

2023-02-1723:15:11
CWE-476
GitHub_M
web.nvd.nist.gov
22
hyperkit
cve-2021-32844
hypervisor
vi_pci_write
denial of service
nvd

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

5.3

Confidence

High

EPSS

0

Percentile

13.2%

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, vi_pci_write has is a call to vc_cfgwrite that does not check for null which when called makes the host crash. This issue may lead to a guest crashing the host causing a denial of service. This issue is fixed in commit 451558fe8aaa8b24e02e34106e3bb9fe41d7ad13.

Affected configurations

Nvd
Vulners
Node
mobyprojecthyperkitRange0.20210107
VendorProductVersionCPE
mobyprojecthyperkit*cpe:2.3:a:mobyproject:hyperkit:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "moby",
    "product": "hyperkit",
    "versions": [
      {
        "version": "0.20210107",
        "status": "affected",
        "lessThanOrEqual": "0.20210107",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

5.3

Confidence

High

EPSS

0

Percentile

13.2%

Related for CVE-2021-32844