CVE-2021-47262·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure liveliness of nested VM-Enter fail tracepoint message Use the __string() machinery provided by the tracing subystem to make a copy of the string literals consumed by the "nested VM-Enter failed" tracepoint. A complete copy is necessary to ensure that the tracepoint can't outlive the data/memory it consumes and deference stale memory. Because the tracepoint itself is defined by kvm, if kvm-intel and/or kvm-amd are built as modules, the memory holding the string literals defined by the vendor modules will be freed when the module is unloaded, whereas the tracepoint and its data in the ring buffer will live until kvm is unloaded (or "indefinitely" if kvm is built-in). This bug has existed since the tracepoint was added, but was recently exposed by a new check in tracing to detect exactly this type of bug. fmt: '%s%s ' current_buffer: ' vmx_dirty_log_t-140127 [003] .... kvm_nested_vmenter_failed: ' WARNING: CPU: 3 PID: 140134 at kernel/trace/trace.c:3759 trace_check_vprintf+0x3be/0x3e0 CPU: 3 PID: 140134 Comm: less Not tainted 5.13.0-rc1-ce2e73ce600a-req #184 Hardware name: ASUS Q87M-E/Q87M-E, BIOS 1102 03/03/2014 RIP: 0010:trace_check_vprintf+0x3be/0x3e0 Code: <0f> 0b 44 8b 4c 24 1c e9 a9 fe ff ff c6 44 02 ff 00 49 8b 97 b0 20 RSP: 0018:ffffa895cc37bcb0 EFLAGS: 00010282 RAX: 0000000000000000 RBX: ffffa895cc37bd08 RCX: 0000000000000027 RDX: 0000000000000027 RSI: 00000000ffffdfff RDI: ffff9766cfad74f8 RBP: ffffffffc0a041d4 R08: ffff9766cfad74f0 R09: ffffa895cc37bad8 R10: 0000000000000001 R11: 0000000000000001 R12: ffffffffc0a041d4 R13: ffffffffc0f4dba8 R14: 0000000000000000 R15: ffff976409f2c000 FS: 00007f92fa200740(0000) GS:ffff9766cfac0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000559bd11b0000 CR3: 000000019fbaa002 CR4: 00000000001726e0 Call Trace: trace_event_printf+0x5e/0x80 trace_raw_output_kvm_nested_vmenter_failed+0x3a/0x60 [kvm] print_trace_line+0x1dd/0x4e0 s_show+0x45/0x150 seq_read_iter+0x2d5/0x4c0 seq_read+0x106/0x150 vfs_read+0x98/0x180 ksys_read+0x5f/0xe0 do_syscall_64+0x40/0xb0 entry_SYSCALL_64_after_hwframe+0x44/0xae
- Severity
- high
- Software
- Kernel
- Fixed in
- 5.12.11
- Published
- 2024-05-21
Affected versions
From: 5.11
Until: 5.12.11
Fixed in: 5.12.11
How to fix this CVE
Update your Linux kernel to version 5.12.11 or later to resolve this memory safety issue in the KVM nested VM-Enter tracepoint. The vulnerability allows kernel module unloading to expose stale memory references when vendor-specific KVM modules (kvm-intel or kvm-amd) are built separately. Apply the patch immediately if you run virtualization workloads on affected kernel versions.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version with `uname -r` and verify it is 5.12.11 or later
- Step 2: Confirm KVM modules are loaded by running `lsmod | grep kvm` to identify if kvm-intel or kvm-amd modules are active
- Step 3: Search system logs for trace buffer warnings with `dmesg | grep -i 'trace_check_vprintf\|stale memory'` to identify past exploitation attempts
- Step 4: Verify the patch was applied by checking kernel release notes: `cat /proc/version` should show kernel 5.12.11 or newer
FAQ
What is CVE-2021-47262?
CVE-2021-47262 is a kernel memory safety vulnerability in the KVM hypervisor's nested VM-Enter tracepoint that fails to properly copy string literals when vendor modules are unloaded, potentially leading to use-after-free memory access in the trace ring buffer.
Is CVE-2021-47262 being actively exploited?
No, this vulnerability is not listed on the CISA KEV catalog and has no public exploits available. However, it was exposed through kernel tracing improvements designed to detect this class of memory bug.
What versions of Kernel are affected by CVE-2021-47262?
Linux kernel versions 5.11 through 5.12.10 are vulnerable. The fix is included in kernel 5.12.11 and all later releases.
How do I check if my server is vulnerable to CVE-2021-47262?
Run `uname -r` to check your kernel version. If it shows a version between 5.11 and 5.12.10, you are vulnerable. For example, kernels like 5.11.0, 5.12.0, 5.12.1 through 5.12.10 all require patching.
Does Defensia detect CVE-2021-47262?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2021-47262 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/796d3bd4ac9316e70c181189318cd2bd98af34bc
- https://git.kernel.org/stable/c/9fb088ce13bc3c59a51260207b487db3e556f275
- https://git.kernel.org/stable/c/d046f724bbd725a24007b7e52b2d675249870888
- https://git.kernel.org/stable/c/f31500b0d437a2464ca5972d8f5439e156b74960
- https://git.kernel.org/stable/c/796d3bd4ac9316e70c181189318cd2bd98af34bc
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-47262. Free for 1 server.
Get started free