Headline
CVE-2021-4032: mishandling of memory error during VCPU construction can lead to DoS
A vulnerability was found in the Linux kernel’s KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memory errors that happens during VCPU construction, which allows an attacker with special user privilege to cause a denial of service. This flaw affects kernel versions prior to 5.15 rc7.
Keywords:
Status:
NEW
Alias:
CVE-2021-4032
Product:
Security Response
Classification:
Other
Component:
vulnerability
Sub Component:
Version:
unspecified
Hardware:
All
OS:
Linux
Priority:
medium
Severity:
medium
Target Milestone:
—
Assignee:
Red Hat Product Security
QA Contact:
Docs Contact:
URL:
Whiteboard:
Depends On:
2029215 2027406 2029213 2029214
Blocks:
2027405 2026965
TreeView+
depends on / blocked
Reported:
2021-11-29 14:55 UTC by Guilherme de Almeida Suckevicz
Modified:
2021-12-20 14:44 UTC (History)
CC List:
44 users (show)
Fixed In Version:
kernel 5.15 rc7
Doc Type:
If docs needed, set a value
Doc Text:
A vulnerability was found in the Linux kernel’s KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memory errors that happens during VCPU construction, which allows an attacker with special user privilege to cause a denial of service.
Clone Of:
Environment:
Last Closed: