High severity7.7NVD Advisory· Published Feb 17, 2023· Updated Jun 17, 2026
CVE-2021-32845
CVE-2021-32845
Description
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, the implementation of qnotify at pci_vtrnd_notify fails to check the return value of vq_getchain. This leads to struct iovec iov; being uninitialized and used to read memory in len = (int) read(sc->vrsc_fd, iov.iov_base, iov.iov_len); when an attacker is able to make vq_getchain fail. This issue may lead to a guest crashing the host causing a denial of service and, under certain circumstance, memory corruption. This issue is fixed in commit 41272a980197917df8e58ff90642d14dec8fe948.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=0.20210107+ 2 more
- (no CPE)range: <=0.20210107
- cpe:2.3:a:mobyproject:hyperkit:*:*:*:*:*:*:*:*range: <=0.20210107
- (no CPE)range: 0.20210107
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.