Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-47262— KVM: x86: Ensure liveliness of nested VM-Enter fail tracepoint message

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。

AI Predicted 5.3 Difficulty: Moderate EPSS 0.23% · P14

Possible ATT&CK Techniques 1 AI

T1057 · Process Discovery

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux 380e0055bc7e4a5c687436ba3ccebb4667836b95< 796d3bd4ac9316e70c181189318cd2bd98af34bc affected
380e0055bc7e4a5c687436ba3ccebb4667836b95< d046f724bbd725a24007b7e52b2d675249870888 affected
380e0055bc7e4a5c687436ba3ccebb4667836b95< 9fb088ce13bc3c59a51260207b487db3e556f275 affected
380e0055bc7e4a5c687436ba3ccebb4667836b95< f31500b0d437a2464ca5972d8f5439e156b74960 affected
5.4 affected
< 5.4 unaffected
5.4.126≤ 5.4.* unaffected
5.10.44≤ 5.10.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-47262

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
KVM: x86: Ensure liveliness of nested VM-Enter fail tracepoint message
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure liveliness of nested VM-Enter fail tracepoint message Use the __string() machinery provided by the tracing subystem to make a copy of the string literals consumed by the "nested VM-Enter failed" tracepoint. A complete copy is necessary to ensure that the tracepoint can't outlive the data/memory it consumes and deference stale memory. Because the tracepoint itself is defined by kvm, if kvm-intel and/or kvm-amd are built as modules, the memory holding the string literals defined by the vendor modules will be freed when the module is unloaded, whereas the tracepoint and its data in the ring buffer will live until kvm is unloaded (or "indefinitely" if kvm is built-in). This bug has existed since the tracepoint was added, but was recently exposed by a new check in tracing to detect exactly this type of bug. fmt: '%s%s ' current_buffer: ' vmx_dirty_log_t-140127 [003] .... kvm_nested_vmenter_failed: ' WARNING: CPU: 3 PID: 140134 at kernel/trace/trace.c:3759 trace_check_vprintf+0x3be/0x3e0 CPU: 3 PID: 140134 Comm: less Not tainted 5.13.0-rc1-ce2e73ce600a-req #184 Hardware name: ASUS Q87M-E/Q87M-E, BIOS 1102 03/03/2014 RIP: 0010:trace_check_vprintf+0x3be/0x3e0 Code: <0f> 0b 44 8b 4c 24 1c e9 a9 fe ff ff c6 44 02 ff 00 49 8b 97 b0 20 RSP: 0018:ffffa895cc37bcb0 EFLAGS: 00010282 RAX: 0000000000000000 RBX: ffffa895cc37bd08 RCX: 0000000000000027 RDX: 0000000000000027 RSI: 00000000ffffdfff RDI: ffff9766cfad74f8 RBP: ffffffffc0a041d4 R08: ffff9766cfad74f0 R09: ffffa895cc37bad8 R10: 0000000000000001 R11: 0000000000000001 R12: ffffffffc0a041d4 R13: ffffffffc0f4dba8 R14: 0000000000000000 R15: ffff976409f2c000 FS: 00007f92fa200740(0000) GS:ffff9766cfac0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000559bd11b0000 CR3: 000000019fbaa002 CR4: 00000000001726e0 Call Trace: trace_event_printf+0x5e/0x80 trace_raw_output_kvm_nested_vmenter_failed+0x3a/0x60 [kvm] print_trace_line+0x1dd/0x4e0 s_show+0x45/0x150 seq_read_iter+0x2d5/0x4c0 seq_read+0x106/0x150 vfs_read+0x98/0x180 ksys_read+0x5f/0xe0 do_syscall_64+0x40/0xb0 entry_SYSCALL_64_after_hwframe+0x44/0xae
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 380e0055bc7e4a5c687436ba3ccebb4667836b95 ~ 796d3bd4ac9316e70c181189318cd2bd98af34bc -
Linux Linux 5.4 -

II. Public POCs for CVE-2021-47262

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-47262

登录查看更多情报信息。

Other References for CVE-2021-47262 (4)

Same Patch Batch · Linux · 2024-05-21 · 361 CVEs total

CVE-2023-52741 9.8 CRITICAL cifs: Fix use-after-free in rdata->read_into_pages()
CVE-2021-47378 9.8 CRITICAL nvme-rdma: destroy cm id before destroy qp to avoid use after free
CVE-2023-52755 9.8 CRITICAL ksmbd: fix slab out of bounds write in smb_inherit_dacl()
CVE-2021-47427 9.8 CRITICAL scsi: iscsi: Fix iscsi_task use after free
CVE-2023-52732 9.8 CRITICAL ceph: blocklist the kclient when receiving corrupted snap trace
CVE-2021-47328 9.8 CRITICAL scsi: iscsi: Fix conn use after free during resets
CVE-2021-47232 9.8 CRITICAL can: j1939: fix Use-after-Free, hold skb ref while in use
CVE-2023-52846 8.8 HIGH hsr: Prevent use after free in prp_create_tagged_frame()
CVE-2023-52769 8.8 HIGH wifi: ath12k: fix htt mlo-offset event locking
CVE-2023-52790 8.8 HIGH swiotlb: fix out-of-bounds TLB allocations with CONFIG_SWIOTLB_DYNAMIC
CVE-2021-47308 8.8 HIGH scsi: libfc: Fix array index out of bound exception
CVE-2021-47390 8.8 HIGH KVM: x86: Fix stack-out-of-bounds memory access from ioapic_write_indirect()
CVE-2023-52801 8.8 HIGH iommufd: Fix missing update of domains_itree after splitting iopt_area
CVE-2023-52776 8.8 HIGH wifi: ath12k: fix dfs-radar and temperature event locking
CVE-2023-52798 8.8 HIGH wifi: ath11k: fix dfs radar event locking
CVE-2021-47388 8.8 HIGH mac80211: fix use-after-free in CCMP/GCMP RX
CVE-2023-52829 8.4 HIGH wifi: ath12k: fix possible out-of-bound write in ath12k_wmi_ext_hal_reg_caps()
CVE-2021-47240 8.4 HIGH net: qrtr: fix OOB Read in qrtr_endpoint_post
CVE-2021-47352 8.4 HIGH virtio-net: Add validation for used length
CVE-2021-47244 8.2 HIGH mptcp: Fix out of bounds when parsing TCP options

Showing top 20 of 361 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2021-47262

No comments yet


Leave a comment