PT-2021-5818 · Xen+2 · Xen+2

M. Vefa Bicakci

+1

·

Published

2021-02-18

·

Updated

2022-05-27

·

CVE-2021-27379

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.11.x
Description The issue is related to a lack of privilege management mechanism in the Xen hypervisor on x86 Intel systems. Exploitation of this issue may allow an attacker to access confidential data, compromise its integrity, and cause a denial of service. The problem occurs because a backport missed a flush, resulting in incorrect IOMMU updates, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access.
Recommendations For Xen versions prior to 4.11.x, consider applying the necessary patches or updates to ensure correct IOMMU updates and prevent unintended DMA access. As a temporary workaround, restrict access to sensitive data and consider disabling DMA access for guest OS users until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00309
CVE-2021-27379
DSA-4888-1
SUSE-SU-2021:1250-1
SUSE-SU-2021:1251-1
SUSE-SU-2021:1252-1
SUSE-SU-2021:1268-1
SUSE-SU-2021_1250-1
SUSE-SU-2021_1268-1

Affected Products

Astra Linux
Suse
Xen