CVE-2021-46977

HIGH

Linux Kernel - Preemption Race Condition in KVM VMX User Return MSR Probing

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Disable preemption when probing user return MSRs Disable preemption when probing a user return MSR via RDSMR/WRMSR. If the MSR holds a different value per logical CPU, the WRMSR could corrupt the host's value if KVM is preempted between the RDMSR and WRMSR, and then rescheduled on a different CPU. Opportunistically land the helper in common x86, SVM will use the helper in a future commit.

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 15.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (12)
Linux/Linux < 5.5
Linux/Linux 4be5341026246870818e28b53202b001426a5aec - 31f29749ee970c251b3a7e5b914108425940d089
Linux/Linux 4be5341026246870818e28b53202b001426a5aec - 5104d7ffcf24749939bea7fdb5378d186473f890
Linux/Linux 4be5341026246870818e28b53202b001426a5aec - 5adcdeb57007ccf8ab7ac20bf787ffb6fafb1a94
Linux/Linux 4be5341026246870818e28b53202b001426a5aec - e3ea1895df719c4ef87862501bb10d95f4177bed
Linux/Linux 5.10.38 - 5.10.*
Linux/Linux 5.11.22 - 5.11.*
Linux/Linux 5.12.5 - 5.12.*
Linux/Linux 5.13
Linux/Linux 5.5
... and 2 more
Published Feb 28, 2024
Tracked Since Feb 18, 2026