CVE-2021-3653
Linux Kernel vulnerability analysis and mitigation

Overview

A flaw was discovered in the KVM's AMD code for supporting SVM nested virtualization (CVE-2021-3653). The vulnerability was identified in the processing of the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "intctl" field, this issue could allow a malicious L1 to enable AVIC support (Advanced Virtual Interrupt Controller) for the L2 guest. The vulnerability affects Linux kernel versions prior to 5.14-rc7 and dates back to kernel 2.6.30 (OpenWall List, [RedHat Bugzilla](https://bugzilla.redhat.com/showbug.cgi?id=1983686)).

Technical details

The vulnerability stems from missing validation of the int_ctl VMCB field in the KVM's AMD code. AVIC is currently not supported with nesting and is not advertised in the L1 CPUID. The issue was initially introduced via commit 3d6368ef580a in kernel 2.6.30. The vulnerability has been assigned a CVSS 3 Severity Score of 8.8 (High) (Ubuntu Security).

Impact

As a result of this vulnerability, the L2 guest would be allowed to read/write physical pages of the host, potentially leading to a crash of the entire system, leak of sensitive data, or potential guest-to-host escape (OpenWall List).

Mitigation and workarounds

The vulnerability can be mitigated by disabling nested virtualization when loading the KVM AMD module using the command: modprobe kvm_amd nested=0. The issue has been fixed in Linux kernel version 5.14-rc7 with the patch commit 0f923e07124df069ba68d8bb12324398f4b6b709 (OpenWall List).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management