cbcvebase.
CVE-2021-22543
published 2021-05-26

CVE-2021-22543: An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.66%
48.0th percentile
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.10.46-2 (bookworm)linux 5.10.46-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-25.10.46-2
linuxlinux_kernel>= 0 < 5.10.46-25.10.46-2
linuxlinux_kernel>= 0 < 5.10.46-25.10.46-2
linuxlinux_kernel>= 0 < 5.10.46-25.10.46-2
linuxlinux_kernel>= 0 < 4.15.0-159.1674.15.0-159.167
linuxlinux_kernel>= 0 < 5.4.0-84.945.4.0-84.94
linux_kernellinux_kernel>= add6a0cd1c5ba51b201e1361b05a5df817083618 < f8be156be163a052a067306417cd0ff679068c97f8be156be163a052a067306417cd0ff679068c97
paloaltopan-os

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.7HIGH
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.