CVE-2021-37576: Input Validation
A flaw was found on the Linux kernel. On the PowerPC platform, the KVM guest allows the OS users to cause host OS memory corruption via rtasargs.nargs. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
arch/powerpc/kvm/book3srtas.c in the Linux kernel on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via syscalls from the guest.
Reference: https://lore.kernel.org/linuxppc-dev/87im0x1lqi.fsf@mpe.ellerman.id.au/T/#u
Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f62f3c20647ebd5fb6ecb8f0b477b9281c44c10a
— Red Hat
arch/powerpc/kvm/book3srtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtasargs.nargs, aka CID-f62f3c20647e.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.45.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-514.93.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.94.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.84.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.59.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.17.1.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.54.2.el8_1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.65.2.el8_2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernel 5.14to a version that resolves this vulnerability.Fixed in 4 - Upgrade
Upgrade
Linux kernel (powerpc KVM book3s RTAS)to a version that resolves this vulnerability.Patch CID-f62f3c20647e
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-37576?
CVE-2021-37576 has a high severity due to its potential impact on data confidentiality, integrity, and system availability.
How do I fix CVE-2021-37576?
To fix CVE-2021-37576, update your kernel to the recommended versions specified by your distribution.
Which systems are affected by CVE-2021-37576?
CVE-2021-37576 affects systems running specific versions of the Linux kernel, particularly on the PowerPC platform.
What type of vulnerability is CVE-2021-37576?
CVE-2021-37576 is a memory corruption vulnerability in the Linux kernel's KVM implementation.
Is there a workaround for CVE-2021-37576?
Currently, there are no documented workarounds for CVE-2021-37576; the best mitigation is to apply the necessary updates.