PT-2021-5824 · Unknown+2 · Cpu Products+2

Cristiano Giuffrida

+3

·

Published

2021-06-09

·

Updated

2022-08-01

·

CVE-2021-26313

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified) CPU products (affected versions not specified)
Description The issue is related to a potential speculative code store bypass in CPU products, which, in conjunction with software vulnerabilities related to speculative execution of overwritten instructions, may cause incorrect speculation and could result in data leakage. Additionally, there is a vulnerability in the Xen hypervisor related to insufficient access control to ports, which could allow an attacker to access confidential data.
Recommendations For Xen, restrict access to sensitive ports to minimize the risk of exploitation. For CPU products, consider disabling speculative execution of overwritten instructions as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00321
CVE-2021-26313
DSA-4931-1

Affected Products

Astra Linux
Cpu Products
Xen