CVE-2021-22543 Vulnerability Details

  /     /     /  

CVE-2021-22543 Metadata Quick Info

CVE Published: 26/05/2021 | CVE Updated: 16/09/2024 | CVE Year: 2021
Source: Google | Vendor: Linux Kernel | Product: Linux Kernel
Status : PUBLISHED

CVE-2021-22543 Description

An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-119
CWE Name: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Source: Linux Kernel

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).