CVE-2021-3653
Published: 16 August 2021
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" field, this issue could allow a malicious L1 to enable AVIC support (Advanced Virtual Interrupt Controller) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape. This flaw affects Linux kernel versions prior to 5.14-rc7.
From the Ubuntu Security Team
Maxim Levitsky discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel did not properly prevent a guest VM from enabling AVIC in nested guest VMs. An attacker in a guest VM could use this to write to portions of the host's physical memory.
Notes
Author | Note |
---|---|
cascardo | trusty libvirt/qemu does not create nested capable VMs by default |
Mitigation
Disable nested virtualisation when loading the KVM AMD module: modprobe kvm_amd nested=0
CVSS 3 base score: 8.8
Status
Package | Release | Status |
---|---|---|
linux-azure-5.8 Launchpad, Ubuntu, Debian |
focal |
Released
(5.8.0-1041.44~20.04.1)
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-hwe Launchpad, Ubuntu, Debian |
bionic |
Ignored
(replaced by linux-hwe-5.4)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Released
(4.15.0-156.163~16.04.1)
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-hwe-5.4 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-84.94~18.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-hwe-5.8 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
focal |
Ignored
(was pending [5.8.0-67.75] now end-of-life)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-hwe-edge Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-hwe-5.4)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Ignored
(superseded by linux-hwe)
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-lts-xenial Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Released
(4.4.0-214.246~14.04.1)
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-aws-5.0 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-aws-5.3)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-aws-5.3 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-aws-5.4)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-aws-5.4 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1056.59~18.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-aws-5.8 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-aws-hwe Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Released
(4.15.0-1111.118~16.04.1)
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-azure Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-azure-5.3)
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Released
(4.15.0-1123.136~14.04.1)
|
|
xenial |
Released
(4.15.0-1123.136~16.04.1)
|
|
impish |
Not vulnerable
(5.13.0-1004.5)
|
|
focal |
Released
(5.4.0-1058.60)
|
|
hirsute |
Released
(5.11.0-1015.16)
|
|
jammy |
Not vulnerable
(5.13.0-1006.7)
|
|
kinetic |
Not vulnerable
(5.15.0-1003.4)
|
|
linux-azure-4.15 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(4.15.0-1123.136)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-azure-5.3 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-azure-5.4)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-azure-5.4 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1058.60~18.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-bluefield Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.4.0-1019.22)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-dell300x Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
bionic |
Released
(4.15.0-1027.32)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-azure-edge Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-azure-5.3)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gcp Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-gcp-5.3)
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
impish |
Not vulnerable
(5.13.0-1003.4)
|
|
xenial |
Released
(4.15.0-1108.122~16.04.1)
|
|
focal |
Released
(5.4.0-1052.56)
|
|
hirsute |
Released
(5.11.0-1018.20)
|
|
jammy |
Not vulnerable
(5.13.0-1005.6)
|
|
kinetic |
Not vulnerable
(5.15.0-1003.6)
|
|
linux-gcp-4.15 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
bionic |
Released
(4.15.0-1108.122)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gcp-5.3 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-gcp-5.4)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gcp-5.4 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1052.56~18.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gcp-5.8 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gcp-edge Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-gcp-5.3)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gke Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Ignored
(reached end of standard support)
|
|
impish |
Does not exist
|
|
focal |
Released
(5.4.0-1052.55)
|
|
jammy |
Not vulnerable
(5.15.0-1002.2)
|
|
kinetic |
Does not exist
|
|
linux-gke-4.15 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gke-5.0 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gke-5.3 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gke-5.4 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1052.55~18.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gkeop Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.4.0-1023.24)
|
|
jammy |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-gkeop-5.4 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1023.24~18.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oracle-5.0 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-oracle-5.3)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oracle-5.3 Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-oracle-5.4)
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oracle-5.4 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1054.58~18.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oracle-5.8 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oem Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
impish |
Does not exist
|
|
xenial |
Ignored
(superseded by linux-hwe)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oem-5.6 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oem-5.10 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.10.0-1045.47)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oem-osp1 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-raspi Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Not vulnerable
(AMD processors only)
|
|
hirsute |
Released
(5.11.0-1017.18)
|
|
focal |
Not vulnerable
(AMD processors only)
|
|
jammy |
Not vulnerable
(AMD processors only)
|
|
kinetic |
Not vulnerable
(AMD processors only)
|
|
linux-raspi2 Launchpad, Ubuntu, Debian |
focal |
Not vulnerable
(AMD processors only)
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
impish |
Does not exist
|
|
xenial |
Not vulnerable
(AMD processors only)
|
|
bionic |
Not vulnerable
(AMD processors only)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-raspi2-5.3 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Not vulnerable
(AMD processors only)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-raspi-5.4 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
bionic |
Not vulnerable
(AMD processors only)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-riscv Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Not vulnerable
(AMD processors only)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Not vulnerable
(AMD processors only)
|
|
hirsute |
Released
(5.11.0-1018.19)
|
|
jammy |
Not vulnerable
(AMD processors only)
|
|
kinetic |
Not vulnerable
(AMD processors only)
|
|
linux-riscv-5.8 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
focal |
Not vulnerable
(AMD processors only)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-snapdragon Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(4.15.0-1112.121)
|
|
xenial |
Not vulnerable
(AMD processors only)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-hwe-5.11 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.11.0-34.36~20.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-riscv-5.11 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.11.0-1018.19~20.04.2)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux Launchpad, Ubuntu, Debian |
bionic |
Released
(4.15.0-156.163)
|
focal |
Released
(5.4.0-84.94)
|
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Ignored
(ESM criteria, not a high on 3.13)
|
|
xenial |
Released
(4.4.0-214.246)
|
|
impish |
Not vulnerable
(5.13.0-16.16)
|
|
hirsute |
Released
(5.11.0-34.36)
|
|
jammy |
Not vulnerable
(5.13.0-19.19)
|
|
kinetic |
Not vulnerable
(5.15.0-25.25)
|
|
Patches: Introduced by 3d6368ef580a4dff012960834bba4e28d3c1430c |
||
linux-aws Launchpad, Ubuntu, Debian |
bionic |
Released
(4.15.0-1111.118)
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Released
(4.4.0-1096.101)
|
|
xenial |
Released
(4.4.0-1132.146)
|
|
impish |
Not vulnerable
(5.13.0-1005.6)
|
|
focal |
Released
(5.4.0-1056.59)
|
|
hirsute |
Released
(5.11.0-1017.18)
|
|
jammy |
Not vulnerable
(5.13.0-1005.6)
|
|
kinetic |
Not vulnerable
(5.15.0-1004.6)
|
|
linux-kvm Launchpad, Ubuntu, Debian |
bionic |
Released
(4.15.0-1099.101)
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Released
(4.4.0-1097.106)
|
|
impish |
Not vulnerable
(5.13.0-1002.2)
|
|
focal |
Released
(5.4.0-1046.48)
|
|
hirsute |
Released
(5.11.0-1015.16)
|
|
jammy |
Not vulnerable
(5.13.0-1004.4)
|
|
kinetic |
Not vulnerable
(5.15.0-1004.4)
|
|
linux-oracle Launchpad, Ubuntu, Debian |
bionic |
Released
(4.15.0-1080.88)
|
upstream |
Released
(5.14~rc7)
|
|
trusty |
Does not exist
|
|
xenial |
Released
(4.15.0-1080.88~16.04.1)
|
|
impish |
Not vulnerable
(5.13.0-1008.10)
|
|
focal |
Released
(5.4.0-1054.58)
|
|
hirsute |
Released
(5.11.0-1017.18)
|
|
jammy |
Not vulnerable
(5.13.0-1008.10)
|
|
kinetic |
Not vulnerable
(5.15.0-1002.4)
|
|
linux-oem-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
focal |
Released
(5.13.0-1012.16)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-aws-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
focal |
Released
(5.11.0-1017.18~20.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-azure-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
focal |
Released
(5.11.0-1015.16~20.04.1)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oracle-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
focal |
Released
(5.11.0-1017.18~20.04.1)
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-ibm Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.4.0-1004.5)
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Not vulnerable
(5.15.0-1002.2)
|
|
kinetic |
Not vulnerable
(5.15.0-1002.2)
|
|
linux-gcp-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Released
(5.11.0-1018.20~20.04.2)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oem-5.14 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
(5.14.0-1004.4)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-intel-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
(5.13.0-1007.7)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-azure-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
(5.13.0-1009.10~20.04.2)
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-hwe-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Not vulnerable
(5.13.0-21.21~20.04.1)
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-aws-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Not vulnerable
(5.13.0-1008.9~20.04.2)
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-fips Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.14~rc7)
|
|
xenial |
Ignored
(out of standard support)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-oracle-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Not vulnerable
(5.13.0-1011.13~20.04.2)
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-gcp-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Not vulnerable
(5.13.0-1008.9~20.04.3)
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-ibm-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Not vulnerable
(5.4.0-1010.11~18.04.2)
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
linux-azure-fde Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Not vulnerable
(5.4.0-1063.66+cvm2.2)
|
|
upstream |
Released
(5.14~rc7)
|
|
jammy |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-lowlatency Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Not vulnerable
(5.15.0-22.22)
|
|
upstream |
Released
(5.14~rc7)
|
|
kinetic |
Not vulnerable
(5.15.0-24.24)
|
|
linux-oem-5.17 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Not vulnerable
(5.17.0-1003.3)
|
|
upstream |
Released
(5.14~rc7)
|
|
kinetic |
Not vulnerable
(5.17.0-1003.3)
|
|
linux-intel-iotg Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Not vulnerable
|
|
upstream |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-intel-iotg-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-lowlatency-hwe-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
jammy |
Does not exist
|
|
upstream |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-hwe-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
jammy |
Does not exist
|
|
upstream |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-aws-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
upstream |
Needs triage
|
|
focal |
Not vulnerable
|
|
kinetic |
Does not exist
|
|
linux-gcp-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
jammy |
Does not exist
|
|
upstream |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-gke-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
jammy |
Does not exist
|
|
upstream |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-azure-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
jammy |
Does not exist
|
|
upstream |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-oracle-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
jammy |
Does not exist
|
|
upstream |
Needs triage
|
|
kinetic |
Does not exist
|
|
linux-azure-fde-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Not vulnerable
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
upstream |
Needs triage
|
|
linux-oem-6.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Needs triage
|
|
kinetic |
Does not exist
|
|
upstream |
Needs triage
|
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3653
- https://github.com/torvalds/linux/commit/3d6368ef580a
- https://www.openwall.com/lists/oss-security/2021/08/16/1
- https://ubuntu.com/security/notices/USN-5062-1
- https://ubuntu.com/security/notices/USN-5070-1
- https://ubuntu.com/security/notices/USN-5071-1
- https://ubuntu.com/security/notices/USN-5072-1
- https://ubuntu.com/security/notices/USN-5073-1
- https://ubuntu.com/security/notices/USN-5071-2
- https://ubuntu.com/security/notices/USN-5082-1
- https://ubuntu.com/security/notices/USN-5073-2
- NVD
- Launchpad
- Debian