SB2021040727 - Denial of service in Linux kernel
Published: April 7, 2021 Updated: July 22, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-36311)
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to an error in arch/x86/kvm/svm/sev.c in Linux kernel, which allows soft lockup by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions).
Remediation
Install update from vendor's website.