PT-2021-5818 · Xen+2 · Xen+2
M. Vefa Bicakci
+1
·
Published
2021-02-18
·
Updated
2022-05-27
·
CVE-2021-27379
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xen versions prior to 4.11.x
Description
The issue is related to a lack of privilege management mechanism in the Xen hypervisor on x86 Intel systems. Exploitation of this issue may allow an attacker to access confidential data, compromise its integrity, and cause a denial of service. The problem occurs because a backport missed a flush, resulting in incorrect IOMMU updates, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access.
Recommendations
For Xen versions prior to 4.11.x, consider applying the necessary patches or updates to ensure correct IOMMU updates and prevent unintended DMA access. As a temporary workaround, restrict access to sensitive data and consider disabling DMA access for guest OS users until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Suse
Xen