CVE-2021-4095
Summary
| CVE | CVE-2021-4095 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:44:00 UTC |
| Updated | 2023-11-07 03:40:00 UTC |
| Description | A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a denial of service by issuing a KVM_XEN_HVM_SET_ATTR ioctl. This flaw affects Linux kernel versions prior to 5.17-rc1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: kernel-tools-5.17.4-100.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: kernel-5.17.4-200.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: kernel-5.17.4-200.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 2031194 – (CVE-2021-4095) CVE-2021-4095 kernel: KVM: NULL pointer dereference in kvm_dirty_ring_get() in virt/kvm/dirty_ring.c |
MISC |
bugzilla.redhat.com |
|
| oss-security - Re: CVE-2021-4095: kernel: KVM: NULL pointer
dereference in kvm_dirty_ring_get() in virt/kvm/dirty_ring.c |
MLIST |
www.openwall.com |
|
| [SECURITY] Fedora 34 Update: kernel-tools-5.17.4-100.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181963 Debian Security Update for linux (CVE-2021-4095)
- 282604 Fedora Security Update for kernel (FEDORA-2022-8efcea6e67)
- 282605 Fedora Security Update for kernel (FEDORA-2022-0816754490)
- 900750 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8944)
- 900873 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8965)
- 902111 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8965-1)
- 905746 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8944-1)
- 906486 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8965-2)