CVE-2021-3501: High severity Linux Linux kernel vulnerability
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
Other sources
A flaw was found in the Linux kernel. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.3.1.rt7.75.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.3.1.el8_4 - Upgrade
Upgrade
redhat/redhat-virtualization-hostto a version that resolves this vulnerability.Fixed in 0:4.4.6-20210615.0.el8_4 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.12 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch 04c4f2ee3f68c9a4bf1653d15f1a9a435ae33f7a - Compensating control
Apply mitigation by updating the Linux kernel as soon as possible, since Red Hat could not identify a practical mitigation example for the KVM out-of-bounds write affecting __vmx_handle_exit() using vcpu->run->internal.ndata.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-3501?
CVE-2021-3501 has a high severity rating due to its impact on data integrity and potential out-of-bounds write issues in the Linux kernel.
How do I fix CVE-2021-3501?
To resolve CVE-2021-3501, upgrade the Linux kernel to version 5.12 or later or apply the relevant patches provided by your distribution.
What versions of Linux are affected by CVE-2021-3501?
CVE-2021-3501 affects Linux kernel versions before 5.12, including specific Red Hat and Debian kernels.
What systems are primarily impacted by CVE-2021-3501?
Systems running vulnerable versions of the Linux kernel, such as earlier versions of Red Hat Enterprise Linux and Debian, are primarily impacted by CVE-2021-3501.
Can CVE-2021-3501 be exploited remotely?
CVE-2021-3501 can potentially be exploited by local users with sufficient privileges to manipulate memory and cause an out-of-bounds write.