← Back

CVE-2021-3656

nvd nist
Published: Mar 4, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD

Description

A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape.

Affected (55)

1 product
Linux Kernel
1 product
Fedora
21 products
Software Collections
Enterprise Linux Desktop
Enterprise Linux For Real Time
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Enterprise Linux Workstation
Openstack
3scale Api Management
Codeready Linux Builder
Virtualization Host
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 4.13 to 4.14.245
From 4.15 to 4.19.205
From 4.20 to 5.4.142
From 5.11 to 5.13.12
From 5.5 to 5.10.60
Version 5.14
Version 5.14 rc1
Version 5.14 rc2
Version 5.14 rc3
Version 5.14 rc4
Version 5.14 rc5
Version 5.14 rc6
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration D
37 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Redhat
Version 7.0
Version 8.0
Redhat
Version 8.1
Version 8.2
Version 8.4
Version 7.0
Version 7.0
Redhat
Version 7
Version 8
Redhat
Version 7
Version 8
Redhat
Version 8.2
Version 8.4
Redhat
Version 8.2
Version 8.4
Version 7.0
Version 7.0
Redhat
Version 7.6
Version 7.7
Version 8.2
Version 8.4
Redhat
Version 7.6
Version 8.1
Version 8.2
Version 8.4
Redhat
Version 7.6
Version 7.7
Version 8.2
Version 8.4
Redhat
Version 7.6
Version 7.7
Version 8.1
Version 8.2
Version 8.4
Version 7.0
Version 13
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0
Configuration F
1 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Redhat
Enterprise Linux Eus
Version 8.1
Redhat
Enterprise Linux Eus
Version 8.2
Redhat
Enterprise Linux Eus
Version 8.4
Redhat
Enterprise Linux For Power Little Endian
Version 8.0
Redhat
Enterprise Linux For Power Little Endian Eus
Version 8.1
Redhat
Enterprise Linux For Power Little Endian Eus
Version 8.2
Redhat
Enterprise Linux For Power Little Endian Eus
Version 8.4
Configuration G
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 4.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Redhat
Enterprise Linux
Version 8.0

References (8)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.