Lucene search

K
osvGoogleOSV:USN-5082-1
HistorySep 16, 2021 - 4:49 p.m.

linux-oem-5.13 vulnerabilities

2021-09-1616:49:22
Google
osv.dev
15
linux
oem
5.13
vulnerabilities
kvm hypervisor
amd processors
guest vm
physical memory
cve-2021-3656
avic
nested guest vms
cve-2021-3653
can bcm
networking protocol
use-after-free
local attacker
arbitrary code

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

35.2%

Maxim Levitsky and Paolo Bonzini discovered that the KVM hypervisor
implementation for AMD processors in the Linux kernel allowed a guest VM to
disable restrictions on VMLOAD/VMSAVE in a nested guest. An attacker in a
guest VM could use this to read or write portions of the host’s physical
memory. (CVE-2021-3656)

Maxim Levitsky discovered that the KVM hypervisor implementation for AMD
processors in the Linux kernel did not properly prevent a guest VM from
enabling AVIC in nested guest VMs. An attacker in a guest VM could use this
to write to portions of the host’s physical memory. (CVE-2021-3653)

Norbert Slusarek discovered a race condition in the CAN BCM networking
protocol of the Linux kernel leading to multiple use-after-free
vulnerabilities. A local attacker could use this issue to execute arbitrary
code. (CVE-2021-3609)