CVE-2021-4093: High severity Linux Linux kernel vulnerability
A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for example, outs or ins) using the exit reason SVMEXITIOIO. This issue results in a crash of the entire system or a potential guest-to-host escape scenario.
Other sources
A KVM guest using SEV-ES (Secure Encrypted Virtualization - Encrypted State) can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT using the exit reason SVMEXITIOIO.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4093?
CVE-2021-4093 has been classified with a high severity rating due to the potential for out-of-bounds reads and writes in the host kernel.
How do I fix CVE-2021-4093?
To fix CVE-2021-4093, ensure your system is updated to kernel version 5.15 or later, or apply the specific patches available for your distribution.
What systems are affected by CVE-2021-4093?
CVE-2021-4093 affects various systems including Red Hat Enterprise Linux 8.0, Fedora 35, and specific versions of Ubuntu Linux.
Can CVE-2021-4093 lead to remote code execution?
Yes, CVE-2021-4093 can potentially allow an attacker to exploit the vulnerability to execute arbitrary code on the host system.
Who is responsible for addressing CVE-2021-4093?
It is the responsibility of system administrators and vendors to monitor for patches and updates related to CVE-2021-4093 to ensure systems remain secure.