CVE-2021-47262 is a vulnerability in the Linux kernel's KVM subsystem, specifically affecting the nested VM-Enter fail tracepoint message. It occurs when KVM-intel or KVM-amd modules are unloaded, leading to the tracepoint attempting to access freed memory. This bug has existed since the tracepoint's inception but was recently exposed by a new tracing subsystem check. The vulnerability has a CVSS score of 7.1 (High), indicating a local attack vector with low attack complexity. A successful exploit could lead to high confidentiality impact and high availability impact, potentially causing system crashes or information disclosure. The CWE is NVD-CWE-noinfo. There is no evidence of active exploitation, nor is exploit code publicly available through Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low public awareness and attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.4, < 5.4.126CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.44CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.12.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.13:rc1:*:*:*:*:*:* | ||
5.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.13:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.