← Retour aux CVEs
CVE-2021-32847
HIGH7.1
Description
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malicious guest can trigger a vulnerability in the host by abusing the disk driver that may lead to the disclosure of the host memory into the virtualized guest. This issue is fixed in commit cf60095a4d8c3cb2e182a14415467afd356e982f.
Details CVE
Score CVSS v3.17.1
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie2/20/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
mobyproject:hyperkit
Faiblesses (CWE)
CWE-125CWE-125
References
https://github.com/moby/hyperkit/blob/2f061e447e1435cdf1b9eda364cea6414f2c606b/src/lib/pci_virtio_block.c#L316(security-advisories@github.com)
https://github.com/moby/hyperkit/commit/cf60095a4d8c3cb2e182a14415467afd356e982f(security-advisories@github.com)
https://securitylab.github.com/advisories/GHSL-2021-058-moby-hyperkit/(security-advisories@github.com)
https://github.com/moby/hyperkit/blob/2f061e447e1435cdf1b9eda364cea6414f2c606b/src/lib/pci_virtio_block.c#L316(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/moby/hyperkit/commit/cf60095a4d8c3cb2e182a14415467afd356e982f(af854a3a-2127-422b-91ae-364da2661108)
https://securitylab.github.com/advisories/GHSL-2021-058-moby-hyperkit/(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.