PT-2021-4064 · Xen+1 · Xen+1

Julien Grall

·

Published

2021-03-10

·

Updated

2021-09-21

·

CVE-2021-28693

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue is related to the Xen hypervisor on Arm, where boot modules such as the kernel and initramfs are not properly scrubbed. This could allow an attacker to access sensitive data. The bootloader loads these modules into a temporary area before they are copied to each domain's memory by Xen. To prevent data leakage, Xen should scrub these modules before allocating the pages. However, it was found that this scrubbing does not occur on Arm platforms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04605
CVE-2021-28693
OPENSUSE-SU-2021:1236-1
OPENSUSE-SU-2021:2923-1
OPENSUSE-SU-2021_1236-1
OPENSUSE-SU-2021_2923-1
SUSE-SU-2021:2922-1
SUSE-SU-2021:2923-1
SUSE-SU-2021:2924-1
SUSE-SU-2021:2925-1

Affected Products

Suse
Xen