PT-2021-4228 · Linux+5 · Linux+5

Nicolai Stange

·

Published

2021-03-01

·

Updated

2022-06-14

·

CVE-2021-28688

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux versions 3.11 and later
Description The issue is related to incorrect initialization of data in the Linux operating system, which can lead to a denial of service. The problem arises from the fix for a previous issue, where the initialization of pointers was implemented to prevent the use of uninitialized or stale values. However, this initialization may overwrite pointers that need to be cleaned up under certain conditions, resulting in a leak of persistent grants. This leak can prevent the full cleanup of resources after a guest has died, leaving behind zombie domains.
Recommendations For Linux versions 3.11 and later, consider disabling the affected cleanup code as a temporary workaround until a proper fix is available. Restrict access to the vulnerable components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1422
ALT-PU-2021-1443
ALT-PU-2021-1447
ALT-PU-2021-1461
ALT-PU-2021-1462
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1869
ALT-PU-2021-1870
BDU:2021-04832
CVE-2021-28688
DLA-2689-1
DLA-2690-1
MGASA-2021-0174
MGASA-2021-0175
OESA-2021-1176
OPENSUSE-SU-2021:0532-1
OPENSUSE-SU-2021:0758-1
OPENSUSE-SU-2021:1975-1
OPENSUSE-SU-2021:1977-1
OPENSUSE-SU-2021_0532-1
OPENSUSE-SU-2021_0758-1
OPENSUSE-SU-2021_1975-1
OPENSUSE-SU-2021_1977-1
SUSE-SU-2021:1175-1
SUSE-SU-2021:1176-1
SUSE-SU-2021:1177-1
SUSE-SU-2021:1210-1
SUSE-SU-2021:1211-1
SUSE-SU-2021:1238-1
SUSE-SU-2021:1341-1
SUSE-SU-2021:1344-1
SUSE-SU-2021:1347-1
SUSE-SU-2021:1365-1
SUSE-SU-2021:1373-1
SUSE-SU-2021:1395-1
SUSE-SU-2021:1573-1
SUSE-SU-2021:1596-1
SUSE-SU-2021:1624-1
SUSE-SU-2021:1625-1
SUSE-SU-2021:1975-1
SUSE-SU-2021:1977-1
SUSE-SU-2021:2026-1
SUSE-SU-2021:2577-1
SUSE-SU-2021:2846-1
SUSE-SU-2021:4052-1
SUSE-SU-2021_1341-1
SUSE-SU-2021_1347-1
SUSE-SU-2022:0668-1
SUSE-SU-2022:1003-1
SUSE-SU-2022:1641-1
SUSE-SU-2022:2077-1
SUSE-SU-2022:2082-1
SUSE-SU-2022_1003-1
SUSE-SU-2022_1641-1
USN-4946-1
USN-4948-1
USN-4982-1
USN-4984-1
USN-5343-1

Affected Products

Alt Linux
Astra Linux
Linux
Linuxmint
Suse
Ubuntu