NULL Pointer Dereference Vulnerability in ACRN Hypervisor
CVE-2021-36146

7.5HIGH

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
2 July 2021

Summary

The ACRN Hypervisor is susceptible to a NULL Pointer Dereference in the devicemodel/hw/pci/xhci.c component. This vulnerability occurs when the TRB (Transfer Request Block) pointer is not properly initialized, leading to potential exploitation scenarios that could compromise the stability and security of the system. It is crucial for users of ACRN Hypervisor versions prior to 2.5 to apply the necessary updates provided in the repository to mitigate this issue.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.