Use-After-Free Vulnerability in ACRN Hypervisor Affecting Virtio Devices
CVE-2021-36144
7.5HIGH
What is CVE-2021-36144?
The ACRN Hypervisor prior to version 2.5 contains a use-after-free vulnerability within the polling timer handler. This issue arises when a freed virtio device is incorrectly referenced, potentially leading to system instability or unintended behavior. The problem is located in the device model code, specifically within the handling of PCI virtio devices, making it critical for system administrators to apply updates to mitigate potential security risks.