PT-2021-4064 · Xen+1 · Xen+1
Julien Grall
·
Published
2021-03-10
·
Updated
2021-09-21
·
CVE-2021-28693
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xen (affected versions not specified)
Description
The issue is related to the Xen hypervisor on Arm, where boot modules such as the kernel and initramfs are not properly scrubbed. This could allow an attacker to access sensitive data. The bootloader loads these modules into a temporary area before they are copied to each domain's memory by Xen. To prevent data leakage, Xen should scrub these modules before allocating the pages. However, it was found that this scrubbing does not occur on Arm platforms.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen