SB2022011910 - Multiple vulnerabilities in Oracle VM Server 



SB2022011910 - Multiple vulnerabilities in Oracle VM Server

Published: January 19, 2022

Security Bulletin ID SB2022011910
Severity
High
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 13% Medium 38% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 secuirty vulnerabilities.


1) Privilege escalation (CVE-ID: CVE-2017-17045)

The vulnerability allows an adjacent attacker to gain elevated privileges on the target system.

The weakness exists due to improper privileges control. An adjacent attacker can trigger a p2m error checking flaw in the Populate on Demand (PoD) code and gain write access to freed memory and gain elevated privileges on the host system.

2) Buffer overflow (CVE-ID: CVE-2021-28706)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error. A remote authenticated attacker can trigger memory corruption and cause a denial of service condition on the target system.


3) Input validation error (CVE-ID: CVE-2021-28709)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in insertion of new pages code path. A remote authenticated attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


4) Use-after-free (CVE-ID: CVE-2021-1048)

The vulnerability allows a malicious application to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in the Android kernel component within the epoll_loop_check_proc() function. A malicious application can trigger a use-after-free error and execute arbitrary code with kernel privileges.

Note, the vulnerability is being actively exploited in the wild.


5) Input validation error (CVE-ID: CVE-2021-28705)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in page removal code path. A remote authenticated attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


6) Use-after-free (CVE-ID: CVE-2021-0920)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the unix_scm_to_skb() function of af_unix.c in Linux kernel. A local user can run a specially crafted program to trigger a race condition and execute arbitrary code with elevated privileges.



7) Infinite loop (CVE-ID: CVE-2017-17044)

The vulnerability allows an adjacent attacker to cause DoS condition on the target system.

The weakness exists due to an infinite loop. An adjacent attacker can trigger an error handling flaw in the processing of errors from the Populate on Demand (PoD) code and cause the service to crash.

8) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-4155)

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to the OS kernel does not impose correctly security restrictions. A local user can gain access to sensitive information on the system.


Remediation

Install update from vendor's website.