CVE-2021-43056: Medium severity linux kernel vulnerability
A denial of service problem was found in KVM specific to powerpc. In this flaw, a user with local access can confuse the host offline code, causing the guest to crash.
References:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cdeb5d7d890e14f3b70e8087e745c4a6a7d9f337
Other sources
A denial of service problem was found in the Linux kernel's Kernel-based Virtual Machine (KVM) specific to PowerPC. In this flaw, a user with local access can confuse the host offline code, causing the guest to crash.
An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3shvrmhandlers.S implementation bug in the handling of the SRR1 register values.
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43056?
CVE-2021-43056 has been classified as a denial of service vulnerability which may have a critical impact in certain environments.
How do I fix CVE-2021-43056?
To mitigate CVE-2021-43056, update to the recommended kernel versions provided by your Linux distribution.
Who is affected by CVE-2021-43056?
CVE-2021-43056 affects users of KVM on powerpc architecture, particularly those with local access.
What impact does CVE-2021-43056 have on systems?
CVE-2021-43056 can cause guest virtual machines to crash, impacting availability.
What versions of kernel are vulnerable to CVE-2021-43056?
Kernel versions prior to 0:4.18.0-372.9.1.el8 and various versions of Linux kernel up to 5.4.15 are vulnerable to CVE-2021-43056.