← Back to CVEs
CVE-2021-32847
HIGH7.1
Description
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malicious guest can trigger a vulnerability in the host by abusing the disk driver that may lead to the disclosure of the host memory into the virtualized guest. This issue is fixed in commit cf60095a4d8c3cb2e182a14415467afd356e982f.
CVE Details
CVSS v3.1 Score7.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published2/20/2023
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
mobyproject:hyperkit
Weaknesses (CWE)
CWE-125CWE-125
References
https://github.com/moby/hyperkit/blob/2f061e447e1435cdf1b9eda364cea6414f2c606b/src/lib/pci_virtio_block.c#L316(security-advisories@github.com)
https://github.com/moby/hyperkit/commit/cf60095a4d8c3cb2e182a14415467afd356e982f(security-advisories@github.com)
https://securitylab.github.com/advisories/GHSL-2021-058-moby-hyperkit/(security-advisories@github.com)
https://github.com/moby/hyperkit/blob/2f061e447e1435cdf1b9eda364cea6414f2c606b/src/lib/pci_virtio_block.c#L316(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/moby/hyperkit/commit/cf60095a4d8c3cb2e182a14415467afd356e982f(af854a3a-2127-422b-91ae-364da2661108)
https://securitylab.github.com/advisories/GHSL-2021-058-moby-hyperkit/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.