Lucene search

K
osvGoogleOSV:USN-5071-3
HistorySep 22, 2021 - 12:34 a.m.

linux-raspi, linux-raspi-5.4 vulnerabilities

2021-09-2200:34:54
Google
osv.dev
4

8.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.9%

It was discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform reference counting in some situations,
leading to a use-after-free vulnerability. An attacker who could start and
control a VM could possibly use this to expose sensitive information or
execute arbitrary code. (CVE-2021-22543)

Murray McAllister discovered that the joystick device interface in the
Linux kernel did not properly validate data passed via an ioctl(). A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code on systems with a joystick device
registered. (CVE-2021-3612)