vulnerability

Oracle Linux: CVE-2020-36310: ELSA-2021-9307: Unbreakable Enterprise kernel-container security update (IMPORTANT) (Multiple Advisories)

Severity
1
CVSS
(AV:L/AC:L/Au:S/C:N/I:N/A:N)
Published
2020-04-21
Added
2021-06-15
Modified
2025-01-23

Description

An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52.
A flaw was found in the Linux kernel. A nested page fault is created when an address does not have a memslot associated to it. The highest threat from this vulnerability is to system availability. This flaw can be triggered using a malformed Virtual Machine. When triggered this bug will lead to the user-space component of KVM to freeze.

Solution

oracle-linux-upgrade-kernel-uek
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.