PT-2021-17907 · Xen+1 · Xen+1

Julien Grall

+1

·

Published

2021-12-01

·

Updated

2024-02-04

·

CVE-2021-28703

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Xen versions prior to 4.14
Description: The issue arises when grant table v2 status pages are de-allocated as a guest switches back from v2 to v1, potentially allowing a guest to retain access to a page that was freed and perhaps re-used for other purposes. This occurs because the hypervisor tracks only one use within guest space, but racing requests from the guest can result in these pages becoming mapped in multiple locations. The majority of such pages remain allocated or associated with a guest for its entire lifetime, but grant table v2 status pages are an exception, getting de-allocated when a guest switches back from v2 to v1.
Recommendations: For versions prior to 4.14, update to Xen 4.14 or a security-supported Xen branch that includes the backported fix. As a temporary workaround, consider restricting access to grant table v2 status pages to minimize the risk of exploitation. Avoid using grant table v2 status pages in multiple locations within guest space until the issue is resolved.

Fix

Related Identifiers

CVE-2021-28703
SUSE-SU-2021:14848-1
SUSE-SU-2021_14848-1

Affected Products

Suse
Xen