CVE-2021-3543

Related Vulnerabilities: CVE-2021-3543  

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.

Description

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.

Statement

This flaw is rated as having a Moderate impact because in the default configuration, the issue can only be triggered by a privileged local user (with access to the ne group if this user manages Enclaves VMs).

This flaw is rated as having a Moderate impact because in the default configuration, the issue can only be triggered by a privileged local user (with access to the ne group if this user manages Enclaves VMs).

Additional Information

  • Bugzilla 1953022: CVE-2021-3543 kernel: nitro_enclaves stale file descriptors on failed usercopy
  • (CWE-416|CWE-476): Use After Free or NULL Pointer Dereference
  • FAQ: Frequently asked questions about CVE-2021-3543