PT-2021-5824 · Unknown+2 · Cpu Products+2
Cristiano Giuffrida
+3
·
Published
2021-06-09
·
Updated
2022-08-01
·
CVE-2021-26313
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xen (affected versions not specified)
CPU products (affected versions not specified)
Description
The issue is related to a potential speculative code store bypass in CPU products, which, in conjunction with software vulnerabilities related to speculative execution of overwritten instructions, may cause incorrect speculation and could result in data leakage. Additionally, there is a vulnerability in the Xen hypervisor related to insufficient access control to ports, which could allow an attacker to access confidential data.
Recommendations
For Xen, restrict access to sensitive ports to minimize the risk of exploitation.
For CPU products, consider disabling speculative execution of overwritten instructions as a temporary workaround until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Side Channel Attack
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Cpu Products
Xen