cbcvebase.
CVE-2021-47277
published 2024-05-21

CVE-2021-47277: In the Linux kernel, the following vulnerability has been resolved: kvm: avoid speculation-based attacks from out-of-range memslot accesses KVM's mechanism for…

PriorityP432high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved: kvm: avoid speculation-based attacks from out-of-range memslot accesses KVM's mechanism for accessing guest memory translates a guest physical address (gpa) to a host virtual address using the right-shifted gpa (also known as gfn) and a struct kvm_memory_slot. The translation is performed in __gfn_to_hva_memslot using the following formula: hva = slot->userspace_addr + (gfn - slot->base_gfn) * PAGE_SIZE It is expected that gfn falls within the boundaries of the guest's physical memory. However, a guest can access invalid physical addresses in such a way that the gfn is invalid. __gfn_to_hva_memslot is called from kvm_vcpu_gfn_to_hva_prot, which first retrieves a memslot through __gfn_to_memslot. While __gfn_to_memslot does check that the gfn falls within the boundaries of the guest's physical memory or not, a CPU can speculate the result of the check and continue execution speculatively using an illegal gfn. The speculation can result in calculating an out-of-bounds hva. If the resulting host virtual address is used to load another guest physical address, this is effectively a Spectre gadget consisting of two consecutive reads, the second of which is data dependent on the first. Right now it's not clear if there are any cases in which this is exploitable. One interesting case was reported by the original author of this patch, and involves visiting guest page tables on x86. Right now these are not vulnerable because the hva read goes through get_user(), which contains an LFENCE speculation barrier. However, there are patches in progress for x86 uaccess.h to mask kernel addresses instead of using LFENCE; once these land, a guest could use speculation to read from the VMM's ring 3 address space. Other architectures such as ARM already use the address masking method, and would be susceptible to this same kind of data-dependent access gadgets. Therefore, this patch proactively protects from these a

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.46-1 (bookworm)linux 5.10.46-1 (bookworm)
linuxlinux
linuxlinux>= 8a7ae055f3533b520401c170ac55e30628b34df5 < 3098b86390a6b9ea52657689f08410baf130ceff3098b86390a6b9ea52657689f08410baf130ceff
linuxlinux>= 8a7ae055f3533b520401c170ac55e30628b34df5 < 740621309b25bbf619b8a0ba5fd50a8e58989441740621309b25bbf619b8a0ba5fd50a8e58989441
linuxlinux>= 8a7ae055f3533b520401c170ac55e30628b34df5 < 361ce3b917aff93123e9e966d8608655c967f438361ce3b917aff93123e9e966d8608655c967f438
linuxlinux>= 8a7ae055f3533b520401c170ac55e30628b34df5 < 22b87fb17a28d37331bb9c1110737627b17f678122b87fb17a28d37331bb9c1110737627b17f6781
linuxlinux>= 8a7ae055f3533b520401c170ac55e30628b34df5 < bff1fbf0cf0712686f1df59a83fba6e31d2746a0bff1fbf0cf0712686f1df59a83fba6e31d2746a0
linuxlinux>= 8a7ae055f3533b520401c170ac55e30628b34df5 < 7af299b97734c7e7f465b42a2139ce4d772469757af299b97734c7e7f465b42a2139ce4d77246975
linuxlinux>= 8a7ae055f3533b520401c170ac55e30628b34df5 < ed0e2a893092c7fcb4ff7ba74e5efce53a6f5940ed0e2a893092c7fcb4ff7ba74e5efce53a6f5940
linuxlinux>= 8a7ae055f3533b520401c170ac55e30628b34df5 < da27a83fd6cc7780fea190e1f5c19e87019da65cda27a83fd6cc7780fea190e1f5c19e87019da65c
linuxlinux_kernel< 4.4.2734.4.273
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 4.10 < 4.14.2374.14.237
linuxlinux_kernel>= 4.15 < 4.19.1954.19.195
linuxlinux_kernel>= 4.20 < 5.4.1265.4.126
linuxlinux_kernel>= 4.5 < 4.9.2734.9.273
linuxlinux_kernel>= 5.11 < 5.12.115.12.11
linuxlinux_kernel>= 5.5 < 5.10.445.10.44

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.