← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-3656

A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:0.66%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

Affected Products & Versions

Vendor Product Affected Versions
linux linux_kernel 5.14
fedoraproject fedora 33, 34
redhat software_collections all
redhat enterprise_linux_server 7.0
redhat openstack 13
redhat enterprise_linux 8.0, 7.0
redhat enterprise_linux_desktop 7.0
redhat enterprise_linux_eus 8.1, 8.2, 8.4
redhat enterprise_linux_for_ibm_z_systems 7.0, 8.0
redhat enterprise_linux_for_ibm_z_systems_eus 8.1, 8.2, 8.4
redhat enterprise_linux_for_power_big_endian 7.0
redhat enterprise_linux_for_power_little_endian 7.0, 8.0
redhat enterprise_linux_for_power_little_endian_eus 8.1, 8.2, 8.4
redhat enterprise_linux_for_real_time 7, 8
redhat enterprise_linux_for_real_time_for_nfv 7, 8
redhat enterprise_linux_for_real_time_for_nfv_tus 8.2, 8.4
redhat enterprise_linux_for_real_time_tus 8.2, 8.4
redhat enterprise_linux_for_scientific_computing 7.0
redhat enterprise_linux_server_aus 7.6, 7.7, 8.2, 8.4
redhat enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 7.6, 8.1, 8.2, 8.4
redhat enterprise_linux_server_tus 7.6, 7.7, 8.2, 8.4
redhat enterprise_linux_server_update_services_for_sap_solutions 7.6, 7.7, 8.1, 8.2, 8.4
redhat enterprise_linux_workstation 7.0
redhat 3scale_api_management 2.0
redhat codeready_linux_builder all
redhat virtualization_host 4.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.658%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2021-07-21T00:00:00
Published2022-03-04T18:41:26
Last Updated2024-08-03T17:01:07

LINK COPIED TO CLIPBOARD