In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Handle SRCU initialization failure during page track init
Check the return of initsrcustruct(), which can fail due to OOM, when initializing the page track mechanism. Lack of checking leads to a NULL pointer deref found by a modified syzkaller.
[Move the call towards the beginning of kvmarchinit_vm. - Paolo]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47407.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.10.71"
}
]
},
{
"events": [
{
"introduced": "5.11"
},
{
"fixed": "5.14.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.15-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.15-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.15-rc3"
}
]
}
]