{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2021-47112","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-03-04T18:12:48.836Z","datePublished":"2024-03-15T20:14:20.602Z","dateUpdated":"2026-08-05T08:46:05.685Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:46:05.685Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/kvm: Teardown PV features on boot CPU as well\n\nVarious PV features (Async PF, PV EOI, steal time) work through memory\nshared with hypervisor and when we restore from hibernation we must\nproperly teardown all these features to make sure hypervisor doesn't\nwrite to stale locations after we jump to the previously hibernated kernel\n(which can try to place anything there). For secondary CPUs the job is\nalready done by kvm_cpu_down_prepare(), register syscore ops to do\nthe same for boot CPU."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in guest-side KVM paravirt code (arch/x86/kernel/kvm.c) and is reached only when the guest performs local hibernation/suspend-to-disk (write to /sys/power/state or logind), not via network packets or adjacent-link protocols.\nAC:L - On a KVM guest with PV features (steal time/PV EOI/async PF), initiating hibernate/resume cycles deterministically leaves boot-CPU PV MSRs enabled so the hypervisor keeps writing shared structures; Ubuntu reproduced reliable memory corruption after repeated hibernate/resume with no attacker-uncontrollable race.\nPR:L - An active local seat user can trigger hibernate/suspend through logind/polkit without real init-namespace root, matching the worst reasonable desktop/laptop KVM-guest deployment; this does not require capabilities obtainable only outside user namespaces.\nUI:N - The attacker initiates hibernation/resume themselves (or the same path is entered by session autosleep); no separate victim action such as mounting a filesystem or opening a crafted file is required.\nS:U - Impact is memory corruption inside the guest kernel from incomplete PV teardown; this is not a guest-to-host escape, IOMMU bypass, or other cross-authority breakout (the host already fully controls guest memory).\nC:H - Hypervisor writes into stale guest GPAs after resume corrupt arbitrary kernel pages that reused those locations (observed page-flag corruption); such kernel memory corruption can be leveraged for information disclosure.\nI:H - The same stale-GPA writes are kernel memory corruption (page metadata and whatever structures land at the still-registered GPAs), which is exploitable for integrity break / control-flow hijacking under the higher-severity memory-corruption guidance.\nA:H - The corruption manifests as BUG: Bad page state / page-allocator failures and can oops/panic or otherwise crash the guest kernel after hibernation resume, fully denying availability."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/kernel/kvm.c"],"versions":[{"version":"fd10cde9294f73eeccbc16f3fec1ae6cde7b800c","lessThan":"7620a669111b52f224d006dea9e1e688e2d62c54","status":"affected","versionType":"git"},{"version":"fd10cde9294f73eeccbc16f3fec1ae6cde7b800c","lessThan":"38b858da1c58ad46519a257764e059e663b59ff2","status":"affected","versionType":"git"},{"version":"fd10cde9294f73eeccbc16f3fec1ae6cde7b800c","lessThan":"d1629b5b925de9b27979e929dae7fcb766daf6b6","status":"affected","versionType":"git"},{"version":"fd10cde9294f73eeccbc16f3fec1ae6cde7b800c","lessThan":"8b79feffeca28c5459458fe78676b081e87c93a4","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/kernel/kvm.c"],"versions":[{"version":"2.6.38","status":"affected"},{"version":"0","lessThan":"2.6.38","status":"unaffected","versionType":"semver"},{"version":"5.4.125","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.43","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.12.10","lessThanOrEqual":"5.12.*","status":"unaffected","versionType":"semver"},{"version":"5.13","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"5.4.125"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"5.10.43"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"5.12.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.38","versionEndExcluding":"5.13"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7620a669111b52f224d006dea9e1e688e2d62c54"},{"url":"https://git.kernel.org/stable/c/38b858da1c58ad46519a257764e059e663b59ff2"},{"url":"https://git.kernel.org/stable/c/d1629b5b925de9b27979e929dae7fcb766daf6b6"},{"url":"https://git.kernel.org/stable/c/8b79feffeca28c5459458fe78676b081e87c93a4"}],"title":"x86/kvm: Teardown PV features on boot CPU as well","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2021-47112","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-03-18T20:26:26.037473Z"}}}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T17:14:29.430Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T05:24:39.829Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/7620a669111b52f224d006dea9e1e688e2d62c54","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/38b858da1c58ad46519a257764e059e663b59ff2","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/d1629b5b925de9b27979e929dae7fcb766daf6b6","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/8b79feffeca28c5459458fe78676b081e87c93a4","tags":["x_transferred"]}]}]}}