CVE-2021-47639: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU

Published Feb 26, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86/mmu: Zap all roots when unmapping gfn range in TDP MMU

Zap both valid and invalid roots when zapping/unmapping a gfn range, as KVM must ensure it holds no references to the freed page after returning from the unmap operation. Most notably, the TDP MMU doesn't zap invalid roots in mmunotifier callbacks. This leads to use-after-free and other issues if the mmunotifier runs to completion while an invalid root zapper yields as KVM fails to honor the requirement that there must be no references to the page after the mmunotifier returns.

The bug is most easily reproduced by hacking KVM to cause a collision between setnxhugepages() and kvmmmunotifierrelease(), but the bug exists between kvmmmunotifierinvalidaterangestart() and memslot updates as well. Invalidating a root ensures pages aren't accessible by the guest, and KVM won't read or write page data itself, but KVM will trigger e.g. kvmsetpfndirty() when zapping SPTEs, and thus completing a zap of an invalid root after the mmunotifier returns is fatal.

WARNING: CPU: 24 PID: 1496 at arch/x86/kvm/../../../virt/kvm/kvmmain.c:173 [kvm] RIP: 0010:kvmiszonedevicepfn+0x96/0xa0 [kvm] Call Trace: <TASK> kvmsetpfndirty+0xa8/0xe0 [kvm] handlechangedspte+0x2ab/0x5e0 [kvm] handlechangedspte+0x2ab/0x5e0 [kvm] handlechangedspte+0x2ab/0x5e0 [kvm] zapgfnrange+0x1f3/0x310 [kvm] kvmtdpmmuzapinvalidatedroots+0x50/0x90 [kvm] kvmmmuzapallfast+0x177/0x1a0 [kvm] setnxhugepages+0xb4/0x190 [kvm] paramattrstore+0x70/0x100 moduleattrstore+0x19/0x30 kernfsfopwriteiter+0x119/0x1b0 newsyncwrite+0x11c/0x1b0 vfswrite+0x1cc/0x270 ksyswrite+0x5f/0xe0 dosyscall64+0x38/0xc0 entrySYSCALL64afterhwframe+0x44/0xae </TASK>

Affected Software

4 affected components
Linux Foundation Linux Kernel
Linux Linux kernel>=5.13<5.15.33
Linux Linux kernel>=5.16<5.16.19
Linux Linux kernel>=5.17<5.17.2

Event History

Feb 26, 2025
CVE Published
via MITRE·01:54 AM
Data Sourced
via MITRE·01:54 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2021-47639?

CVE-2021-47639 has a high severity rating due to potential exploitation in the Linux kernel affecting memory management.

2

How do I fix CVE-2021-47639?

To fix CVE-2021-47639, update the Linux kernel to the latest version where the vulnerability has been resolved.

3

Which systems are affected by CVE-2021-47639?

CVE-2021-47639 affects systems running certain versions of the Linux kernel that use KVM for virtual memory management.

4

What type of vulnerability is CVE-2021-47639?

CVE-2021-47639 is a memory management vulnerability related to the KVM module in the Linux kernel.

5

Can CVE-2021-47639 lead to remote code execution?

While CVE-2021-47639 primarily affects memory management, successful exploitation could potentially lead to unauthorized access or denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203