We found results for “”
CVE-2021-32846
Date: February 16, 2023
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function "pci_vtsock_proc_tx" in "virtio-sock" can lead to to uninitialized memory use. In this situation, there is a check for the return value to be less or equal to "VTSOCK_MAXSEGS", but that check is not sufficient because the function can return "-1" if it finds an error it cannot recover from. Moreover, the negative return value will be used by "iovec_pull" in a while condition that can further lead to more corruption because the function is not designed to handle a negative "iov_len". This issue may lead to a guest crashing the host causing a denial of service and, under certain circumstance, memory corruption. This issue is fixed in commit af5eba2360a7351c08dfd9767d9be863a50ebaba.
Language: C
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | LOCAL |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


