Database/Kernel, userspace & hypervisor

KVM: Improper handling of VM_IO/VM_PFNMAP vmas in KVM lets a guest bypass read-only checks
CVE-2021-22543Kernel, userspace & hypervisorcurated
Impact
Improper handling of VM_IO/VM_PFNMAP vmas in KVM lets a guest bypass read-only checks - host privilege escalation
Who can reach it
Tenant VM guest / local user with /dev/kvm
What to do
Kernel patch. Livepatchable on some vendors; KVM module changes often are not - budget drain + reboot
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.