Database/Kernel, userspace & hypervisor

KVM: Improper handling of VM_IO/VM_PFNMAP vmas in KVM lets a guest bypass read-only checks
CVSS 7.0CVE-2021-22543Kernel, userspace & hypervisorcurated
Impact
Improper handling of VM_IO/VM_PFNMAP vmas in KVM lets a guest bypass read-only checks - host privilege escalation
Who can reach it
Tenant VM guest / local user with /dev/kvm
What to do
Kernel patch. Livepatchable on some vendors; KVM module changes often are not - budget drain + reboot
References
Related entries
- KVM: NULL pointer dereference in kvm_irq_delivery_to_apic_fast() - guest crashes the hostCVE-2022-2153 · KVMMedium
- Linux kernel (af_packet): Double free in packet_set_ring(), local privilege escalationCVE-2021-22600 · Linux kernel (af_packet)High
- Linux kernel (eBPF): eBPF improper input validation leading to local privilege escalationCVE-2021-4204 · Linux kernel (eBPF)High
- Linux kernel (cgroups v1): cgroups v1 release_agent lets a container with CAP_SYS_ADMIN (or an unconfined userns) runCVE-2022-0492 · Linux kernel (cgroups v1)High
- Linux kernel (io_uring): Use-after-free between io_uring and the unix GC - local rootCVE-2022-2602 · Linux kernel (io_uring)High
- Linux kernel (OverlayFS/FUSE): OverlayFS copies setuid files from a nosuid FUSE mountCVE-2023-0386 · Linux kernel (OverlayFS/FUSE)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.