CVE-2021-47277
published 2024-05-21CVE-2021-47277: In the Linux kernel, the following vulnerability has been resolved: kvm: avoid speculation-based attacks from out-of-range memslot accesses KVM's mechanism for…
PriorityP432high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
kvm: avoid speculation-based attacks from out-of-range memslot accesses
KVM's mechanism for accessing guest memory translates a guest physical
address (gpa) to a host virtual address using the right-shifted gpa
(also known as gfn) and a struct kvm_memory_slot. The translation is
performed in __gfn_to_hva_memslot using the following formula:
hva = slot->userspace_addr + (gfn - slot->base_gfn) * PAGE_SIZE
It is expected that gfn falls within the boundaries of the guest's
physical memory. However, a guest can access invalid physical addresses
in such a way that the gfn is invalid.
__gfn_to_hva_memslot is called from kvm_vcpu_gfn_to_hva_prot, which first
retrieves a memslot through __gfn_to_memslot. While __gfn_to_memslot
does check that the gfn falls within the boundaries of the guest's
physical memory or not, a CPU can speculate the result of the check and
continue execution speculatively using an illegal gfn. The speculation
can result in calculating an out-of-bounds hva. If the resulting host
virtual address is used to load another guest physical address, this
is effectively a Spectre gadget consisting of two consecutive reads,
the second of which is data dependent on the first.
Right now it's not clear if there are any cases in which this is
exploitable. One interesting case was reported by the original author
of this patch, and involves visiting guest page tables on x86. Right
now these are not vulnerable because the hva read goes through get_user(),
which contains an LFENCE speculation barrier. However, there are
patches in progress for x86 uaccess.h to mask kernel addresses instead of
using LFENCE; once these land, a guest could use speculation to read
from the VMM's ring 3 address space. Other architectures such as ARM
already use the address masking method, and would be susceptible to
this same kind of data-dependent access gadgets. Therefore, this patch
proactively protects from these a
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.46-1 (bookworm) | linux 5.10.46-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 8a7ae055f3533b520401c170ac55e30628b34df5 < 3098b86390a6b9ea52657689f08410baf130ceff | 3098b86390a6b9ea52657689f08410baf130ceff |
| linux | linux | >= 8a7ae055f3533b520401c170ac55e30628b34df5 < 740621309b25bbf619b8a0ba5fd50a8e58989441 | 740621309b25bbf619b8a0ba5fd50a8e58989441 |
| linux | linux | >= 8a7ae055f3533b520401c170ac55e30628b34df5 < 361ce3b917aff93123e9e966d8608655c967f438 | 361ce3b917aff93123e9e966d8608655c967f438 |
| linux | linux | >= 8a7ae055f3533b520401c170ac55e30628b34df5 < 22b87fb17a28d37331bb9c1110737627b17f6781 | 22b87fb17a28d37331bb9c1110737627b17f6781 |
| linux | linux | >= 8a7ae055f3533b520401c170ac55e30628b34df5 < bff1fbf0cf0712686f1df59a83fba6e31d2746a0 | bff1fbf0cf0712686f1df59a83fba6e31d2746a0 |
| linux | linux | >= 8a7ae055f3533b520401c170ac55e30628b34df5 < 7af299b97734c7e7f465b42a2139ce4d77246975 | 7af299b97734c7e7f465b42a2139ce4d77246975 |
| linux | linux | >= 8a7ae055f3533b520401c170ac55e30628b34df5 < ed0e2a893092c7fcb4ff7ba74e5efce53a6f5940 | ed0e2a893092c7fcb4ff7ba74e5efce53a6f5940 |
| linux | linux | >= 8a7ae055f3533b520401c170ac55e30628b34df5 < da27a83fd6cc7780fea190e1f5c19e87019da65c | da27a83fd6cc7780fea190e1f5c19e87019da65c |
| linux | linux_kernel | < 4.4.273 | 4.4.273 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 4.10 < 4.14.237 | 4.14.237 |
| linux | linux_kernel | >= 4.15 < 4.19.195 | 4.19.195 |
| linux | linux_kernel | >= 4.20 < 5.4.126 | 5.4.126 |
| linux | linux_kernel | >= 4.5 < 4.9.273 | 4.9.273 |
| linux | linux_kernel | >= 5.11 < 5.12.11 | 5.12.11 |
| linux | linux_kernel | >= 5.5 < 5.10.44 | 5.10.44 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6239-6f98-f8vf: In the Linux kernel, the following vulnerability has been resolved:
kvm: avoid speculation-based attacks from out-of-range memslot accesses
KVM's me
ghsa_unreviewed·2024-05-21
CVE-2021-47277 [HIGH] CWE-125 GHSA-6239-6f98-f8vf: In the Linux kernel, the following vulnerability has been resolved:
kvm: avoid speculation-based attacks from out-of-range memslot accesses
KVM's me
In the Linux kernel, the following vulnerability has been resolved:
kvm: avoid speculation-based attacks from out-of-range memslot accesses
KVM's mechanism for accessing guest memory translates a guest physical
address (gpa) to a host virtual address using the right-shifted gpa
(also known as gfn) and a struct kvm_memory_slot. The translation is
performed in __gfn_to_hva_memslot using the following formula:
hva = slot->userspace_addr + (gfn - slot->base_gfn) * PAGE_SIZE
It is expected that gfn falls within the boundaries of the guest's
physical memory. However, a guest can access invalid physical addresses
in such a way that the gfn is invalid.
__gfn_to_hva_memslot is called from kvm_vcpu_gfn_to_hva_prot, which first
retrieves a memslot through __gfn_to_memslot. While __gfn_to_memslot
OSV
CVE-2021-47277: In the Linux kernel, the following vulnerability has been resolved: kvm: avoid speculation-based attacks from out-of-range memslot accesses KVM's mech
osv·2024-05-21·CVSS 7.1
CVE-2021-47277 [HIGH] CVE-2021-47277: In the Linux kernel, the following vulnerability has been resolved: kvm: avoid speculation-based attacks from out-of-range memslot accesses KVM's mech
In the Linux kernel, the following vulnerability has been resolved: kvm: avoid speculation-based attacks from out-of-range memslot accesses KVM's mechanism for accessing guest memory translates a guest physical address (gpa) to a host virtual address using the right-shifted gpa (also known as gfn) and a struct kvm_memory_slot. The translation is performed in __gfn_to_hva_memslot using the following formula: hva = slot->userspace_addr + (gfn - slot->base_gfn) * PAGE_SIZE It is expected that gfn falls within the boundaries of the guest's physical memory. However, a guest can access invalid physical addresses in such a way that the gfn is invalid. __gfn_to_hva_memslot is called from kvm_vcpu_gfn_to_hva_prot, which first retrieves a memslot through __gfn_to_memslot. While __gfn_to_memslot does
Red Hat
kernel: kvm: avoid speculation-based attacks from out-of-range memslot accesses
vendor_redhat·2024-05-21·CVSS 7.1
CVE-2021-47277 [HIGH] CWE-118 kernel: kvm: avoid speculation-based attacks from out-of-range memslot accesses
kernel: kvm: avoid speculation-based attacks from out-of-range memslot accesses
In the Linux kernel, the following vulnerability has been resolved:
kvm: avoid speculation-based attacks from out-of-range memslot accesses
KVM's mechanism for accessing guest memory translates a guest physical
address (gpa) to a host virtual address using the right-shifted gpa
(also known as gfn) and a struct kvm_memory_slot. The translation is
performed in __gfn_to_hva_memslot using the following formula:
hva = slot->userspace_addr + (gfn - slot->base_gfn) * PAGE_SIZE
It is expected that gfn falls within the boundaries of the guest's
physical memory. However, a guest can access invalid physical addresses
in such a way that the gfn is invalid.
__gfn_to_hva_memslot is called from kvm_vcpu_gfn_to_hva_prot, whic
Debian
CVE-2021-47277: linux - In the Linux kernel, the following vulnerability has been resolved: kvm: avoid ...
vendor_debian·2021·CVSS 7.1
CVE-2021-47277 [HIGH] CVE-2021-47277: linux - In the Linux kernel, the following vulnerability has been resolved: kvm: avoid ...
In the Linux kernel, the following vulnerability has been resolved: kvm: avoid speculation-based attacks from out-of-range memslot accesses KVM's mechanism for accessing guest memory translates a guest physical address (gpa) to a host virtual address using the right-shifted gpa (also known as gfn) and a struct kvm_memory_slot. The translation is performed in __gfn_to_hva_memslot using the following formula: hva = slot->userspace_addr + (gfn - slot->base_gfn) * PAGE_SIZE It is expected that gfn falls within the boundaries of the guest's physical memory. However, a guest can access invalid physical addresses in such a way that the gfn is invalid. __gfn_to_hva_memslot is called from kvm_vcpu_gfn_to_hva_prot, which first retrieves a memslot through __gfn_to_memslot. While __gfn_to_memslot does
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/22b87fb17a28d37331bb9c1110737627b17f6781https://git.kernel.org/stable/c/3098b86390a6b9ea52657689f08410baf130ceffhttps://git.kernel.org/stable/c/361ce3b917aff93123e9e966d8608655c967f438https://git.kernel.org/stable/c/740621309b25bbf619b8a0ba5fd50a8e58989441https://git.kernel.org/stable/c/7af299b97734c7e7f465b42a2139ce4d77246975https://git.kernel.org/stable/c/bff1fbf0cf0712686f1df59a83fba6e31d2746a0https://git.kernel.org/stable/c/da27a83fd6cc7780fea190e1f5c19e87019da65chttps://git.kernel.org/stable/c/ed0e2a893092c7fcb4ff7ba74e5efce53a6f5940https://git.kernel.org/stable/c/22b87fb17a28d37331bb9c1110737627b17f6781https://git.kernel.org/stable/c/3098b86390a6b9ea52657689f08410baf130ceffhttps://git.kernel.org/stable/c/361ce3b917aff93123e9e966d8608655c967f438https://git.kernel.org/stable/c/740621309b25bbf619b8a0ba5fd50a8e58989441https://git.kernel.org/stable/c/7af299b97734c7e7f465b42a2139ce4d77246975https://git.kernel.org/stable/c/bff1fbf0cf0712686f1df59a83fba6e31d2746a0https://git.kernel.org/stable/c/da27a83fd6cc7780fea190e1f5c19e87019da65chttps://git.kernel.org/stable/c/ed0e2a893092c7fcb4ff7ba74e5efce53a6f5940
2024-05-21
Published