Review reviewHigh

CVE-2021-47341

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: KVM: mmio: Fix use-after-free Read in kvm_vm_ioctl_unregister_coalesced_mmio BUG: KASAN: use-after-free in kvm_vm_ioctl_unregister_coalesced_mmio+0x7c/0x1ec arch/arm64/kvm/../../../virt/kvm/coalesced_mmio.c:183 Read of size 8 at addr ffff0000c03a2500 by task syz-executor083/4269 CPU: 5 PID: 4269 Comm: syz-executor083 Not tainted 5.10.0 #7 Hardware name: linux,dummy-virt (DT) Call trace: dump_backtrace+0x0/0x2d0 arch/arm64/kernel/stacktrace.c:132 show_stack+0x28/0x34 arch/arm64/kernel/stacktrace.c:196 __dump_stack lib/dump_s...

CVSS
7.8
EPSS
0.25%
16.6% percentile
CISA KEV
Not listed
Published
2024.05.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.25%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: KVM: mmio: Fix use-after-free Read in kvm_vm_ioctl_unregister_coalesced_mmio BUG: KASAN: use-after-free in kvm_vm_ioctl_unregister_coalesced_mmio+0x7c/0x1ec arch/arm64/kvm/../../../virt/kvm/coalesced_mmio.c:183 Read of size 8 at addr ffff0000c03a2500 by task syz-executor083/4269 CPU: 5 PID: 4269 Comm: syz-executor083 Not tainted 5.10.0 #7 Hardware name: linux,dummy-virt (DT) Call trace: dump_backtrace+0x0/0x2d0 arch/arm64/kernel/stacktrace.c:132 show_stack+0x28/0x34 arch/arm64/kernel/stacktrace.c:196 __dump_stack lib/dump_s...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 7d1bc32d6477ff96a32695ea4be8144e4513ab2d < f2ff9d03432fcb160e9f7d4be26174d89de2779a, >= 2a20592baff59c5351c5200ec667e1a2aa22af85 < 679837dc0abaa2c6e2a7bcd86483e05eee1d5066, >= 50cbad42bfea8c052b7ca590bd4126cdc898713c < 8d7c539316d652d217e5e82b89ee204c812a7061, >= 5d3c4c79384af06e3c8e25b7770b6247496b4417 < 069d44a24c0ff8f85adf49233aae7a8ca16f5c7e, >= 5d3c4c79384af06e3c8e25b7770b6247496b4417 < 23fa2e46a5556f787ce2ea1a315d3ab93cced204, >= 168e82f640ed1891a700bdb43e37da354b2ab63c, >= 5.4.119 < 5.4.134, >= 5.10.37 < 5.10.52, >= 5.12.4 < 5.12.19, >= 5.11.21 < 5.12, >= 5.13, >= 5.13 < 5.13.4, 5.14
Fixed versions
5.4.134, 5.10.52, 5.12, 5.12.19, 5.13.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2021-47341 — Linux Linux, linux kernel | SECUFOCUS NOW