Wind River Support Network

HomeDefectsLIN1021-1227
Fixed

LIN1021-1227 : Security Advisory - linux - CVE-2021-3656 (KVM)

Created: Aug 16, 2021    Updated: Mar 15, 2022
Resolved Date: Sep 7, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.4
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

This issue is caused by missing validation of the the `virt_ext` VMCB field and allows a malicious L1 guest to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. Under
these circumstances, the L2 guest is able to run VMLOAD/VMSAVE unintercepted, and thus read/write portions of the host physical memory.

https://git.kernel.org/pub/scm/virt/kvm/kvm.git/commit/?id=c7dfa4009965a9b2d7b329ee970eb8da0d32f0bc

CREATE(Triage):(User=admin) CVE-2021-3656 (https://nvd.nist.gov/vuln/detail/CVE-2021-3656)

CVEs


Live chat
Online