CVE-2021-4095

Source
https://cve.org/CVERecord?id=CVE-2021-4095
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-4095.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-4095
Downstream
Published
2022-03-10T17:44:53.563Z
Modified
2026-03-14T11:10:59.842786Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a denial of service by issuing a KVMXENHVMSETATTR ioctl. This flaw affects Linux kernel versions prior to 5.17-rc1.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-4095.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "5.16"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "34"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "35"
            }
        ]
    }
]