PT-2021-6804 · Xen+1 · Xen+1

Jan Beulich

·

Published

2021-08-27

·

Updated

2022-09-28

·

CVE-2021-28697

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue is related to the management of grant table v2 status pages in Xen. When a guest switches from v2 to v1, these pages get de-allocated, but the hypervisor may not correctly track their mapping within the guest space. This can lead to a situation where a guest retains access to a page that was freed and potentially re-used for other purposes, allowing an attacker to access confidential data, disrupt its integrity, or cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02227
CVE-2021-28697
DSA-4977-1
OPENSUSE-SU-2021:1236-1
OPENSUSE-SU-2021:2923-1
OPENSUSE-SU-2021_1236-1
OPENSUSE-SU-2021_2923-1
SUSE-SU-2021:14848-1
SUSE-SU-2021:2922-1
SUSE-SU-2021:2923-1
SUSE-SU-2021:2924-1
SUSE-SU-2021:2925-1
SUSE-SU-2021:2943-1
SUSE-SU-2021:2955-1
SUSE-SU-2021:2957-1
SUSE-SU-2021:3322-1
SUSE-SU-2021_14848-1

Affected Products

Suse
Xen