High severity7.4NVD Advisory· Published Jul 22, 2021· Updated Jun 17, 2026
CVE-2021-29657
CVE-2021-29657
Description
arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass access control on host OS MSRs when there are nested guests, aka CID-a58d9166a756. This occurs because of a TOCTOU race condition associated with a VMCB12 double fetch in nested_svm_vmrun.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Linux/Linux kerneldescription
- Range: <5.11.12
Patches
Vulnerability mechanics
References
5- git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/nvdPatchThird Party Advisory
- bugs.chromium.org/p/project-zero/issues/detailnvdExploitMailing ListPatchThird Party Advisory
- cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.12nvdExploitPatchVendor Advisory
- packetstormsecurity.com/files/163324/KVM-nested_svm_vmrun-Double-Fetch.htmlnvdThird Party AdvisoryVDB Entry
- security.netapp.com/advisory/ntap-20210902-0008/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.