CVE-2021-45464

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
15/04/2023
Last modified:
06/02/2025

Description

kvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest OS user to execute arbitrary code on the host machine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kvmtool_project:kvmtool:-:*:*:*:*:*:*:*