漏洞信息详情
KVM AMD 代码安全漏洞
漏洞简介
KVM是基于内核的虚拟机。
KVM 的 AMD 代码中存在安全漏洞,该漏洞源于在处理 L1 来宾提供的 VMCB(虚拟机控制块)以生成/处理嵌套来宾 (L2) 时对“virt_ext”的不正确验证。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://git.kernel.org/pub/scm/virt/kvm/kvm.git/commit/?id=c7dfa4009965a9b2d7b329ee970eb8da0d32f0bc
参考网址
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3206
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164193/Ubuntu-Security-Notice-USN-5073-2.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3034
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164652/Red-Hat-Security-Advisory-2021-3987-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3456
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3136
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3499
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3554
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3070
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-3656
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164315/Red-Hat-Security-Advisory-2021-3676-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3470
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164583/Red-Hat-Security-Advisory-2021-3949-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3878
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Linux-kernel-read-write-access-via-KVM-Nested-VMLOAD-VMSAVE-36151
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164484/Red-Hat-Security-Advisory-2021-3802-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164747/Red-Hat-Security-Advisory-2021-4088-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164948/Red-Hat-Security-Advisory-2021-4618-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3934
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3222
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3243
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3485
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3661
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3225
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3147
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164478/Red-Hat-Security-Advisory-2021-3812-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3389
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164562/Red-Hat-Security-Advisory-2021-3925-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164993/Red-Hat-Security-Advisory-2021-4628-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3185
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164100/Ubuntu-Security-Notice-USN-5072-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164547/Red-Hat-Security-Advisory-2021-3909-01.html
受影响实体
暂无
补丁
- KVM AMD 代码安全漏洞的修复措施<!--2021-8-16-->
还没有评论,来说两句吧...