First published: Fri Jul 23 2021(Updated: )
A flaw was found on the Linux kernel. On the PowerPC platform, the KVM guest allows the OS users to cause host OS memory corruption via rtas_args.nargs. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <0:3.10.0-1160.45.1.el7 | 0:3.10.0-1160.45.1.el7 |
redhat/kernel | <0:3.10.0-514.93.1.el7 | 0:3.10.0-514.93.1.el7 |
redhat/kernel | <0:3.10.0-693.94.1.el7 | 0:3.10.0-693.94.1.el7 |
redhat/kernel | <0:3.10.0-957.84.1.el7 | 0:3.10.0-957.84.1.el7 |
redhat/kernel | <0:3.10.0-1062.59.1.el7 | 0:3.10.0-1062.59.1.el7 |
redhat/kernel | <0:4.18.0-305.17.1.el8_4 | 0:4.18.0-305.17.1.el8_4 |
redhat/kernel | <0:4.18.0-147.54.2.el8_1 | 0:4.18.0-147.54.2.el8_1 |
redhat/kernel | <0:4.18.0-193.65.2.el8_2 | 0:4.18.0-193.65.2.el8_2 |
redhat/kernel 5.14 | <4 | 4 |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 | |
Linux Kernel | >=3.10<4.4.277 | |
Linux Kernel | >=4.5<4.9.277 | |
Linux Kernel | >=4.10<4.14.241 | |
Linux Kernel | >=4.15<4.19.199 | |
Linux Kernel | >=4.20<5.4.136 | |
Linux Kernel | >=5.5<5.10.54 | |
Linux Kernel | >=5.11<5.13.6 | |
Fedora | =33 | |
Fedora | =34 |
Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-37576 has a high severity due to its potential impact on data confidentiality, integrity, and system availability.
To fix CVE-2021-37576, update your kernel to the recommended versions specified by your distribution.
CVE-2021-37576 affects systems running specific versions of the Linux kernel, particularly on the PowerPC platform.
CVE-2021-37576 is a memory corruption vulnerability in the Linux kernel's KVM implementation.
Currently, there are no documented workarounds for CVE-2021-37576; the best mitigation is to apply the necessary updates.