Vulnerability Description
arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.10, < 4.4.277 |
| Fedoraproject | Fedora | 33 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2021/07/27/2ExploitMailing ListPatch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f6PatchVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lore.kernel.org/linuxppc-dev/87im0x1lqi.fsf%40mpe.ellerman.id.au/T/#u
- https://security.netapp.com/advisory/ntap-20210917-0005/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4978Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/07/27/2ExploitMailing ListPatch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f6PatchVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lore.kernel.org/linuxppc-dev/87im0x1lqi.fsf%40mpe.ellerman.id.au/T/#u
- https://security.netapp.com/advisory/ntap-20210917-0005/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4978Third Party Advisory
FAQ
What is CVE-2021-37576?
CVE-2021-37576 is a vulnerability with a CVSS score of 7.8 (HIGH). arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.
How severe is CVE-2021-37576?
CVE-2021-37576 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37576?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Fedoraproject Fedora.