PT-2021-6804 · Xen+1 · Xen+1
Jan Beulich
·
Published
2021-08-27
·
Updated
2022-09-28
·
CVE-2021-28697
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xen (affected versions not specified)
Description
The issue is related to the management of grant table v2 status pages in Xen. When a guest switches from v2 to v1, these pages get de-allocated, but the hypervisor may not correctly track their mapping within the guest space. This can lead to a situation where a guest retains access to a page that was freed and potentially re-used for other purposes, allowing an attacker to access confidential data, disrupt its integrity, or cause a denial of service.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Race Condition
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Xen