CVE-2021-32847
Last modified
CVE-2021-32847 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malicious guest can trigger a vulnerability in the host by abusing the disk driver that may lead to the disclosure of the host memory into the virtualized guest. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malicious guest can trigger a vulnerability in the host by abusing the disk driver that may lead to the disclosure of the host memory into the virtualized guest. This issue is fixed in commit cf60095a4d8c3cb2e182a14415467afd356e982f.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mobyproject | Hyperkit | <= 0.20210107 |
References
- https://securitylab.github.com/advisories/GHSL-2021-058-moby-hyperkit/Exploit, Third Party Advisory
- https://securitylab.github.com/advisories/GHSL-2021-058-moby-hyperkit/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32847?
How severe is CVE-2021-32847?
How do I fix CVE-2021-32847?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32841SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 libra…5.3
- CVE-2021-32842SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 libra…5.3
- CVE-2021-32843HyperKit is a toolkit for embedding hypervisor capabilities …5.5
- CVE-2021-32844HyperKit is a toolkit for embedding hypervisor capabilities …5.5
- CVE-2021-32845HyperKit is a toolkit for embedding hypervisor capabilities …7.8
- CVE-2021-32846HyperKit is a toolkit for embedding hypervisor capabilities …7.8
- CVE-2021-32848Octobox is software for managing GitHub notifications. Prior…7.5
- CVE-2021-32849Gerapy is a distributed crawler management framework. Prior …8.8
- CVE-2021-3285jxbrowser in TI Code Composer Studio IDE 8.x through 10.x be…5.3
- CVE-2021-32850jQuery MiniColors is a color picker built on jQuery. Prior t…6.1
- CVE-2021-32851Mind-elixir is a free, open source mind map core. Prior to v…6.1
- CVE-2021-32852Countly, a product analytics solution, is vulnerable to cros…9
Are you affected by CVE-2021-32847?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
