Total vulnerabilities in the database
A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.
Software | From | Fixed in |
---|---|---|
linux / linux_kernel | 5.11 | 5.15.33 |
linux / linux_kernel | 5.17 | 5.17.2 |
linux / linux_kernel | 5.5 | 5.10.110 |
linux / linux_kernel | 5.16 | 5.16.19 |
linux / linux_kernel | 5.2 | 5.4.189 |
fedoraproject / fedora | 36 | 36.x |
redhat / enterprise_linux | 8.0 | 8.0.x |
redhat / enterprise_linux | 9.0 | 9.0.x |