CVE-2021-28693
Last modified
CVE-2021-28693 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive data is not leaked from the modules, Xen must "scrub" them before handing the page over to the allocator. Unfortunately, it was discovered that modules will not be scrubbed on Arm.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Xen | Xen | >= 4.12.0, <= 4.15.0 | — |
| Xen | Xen | 4.15.0 | Rc1 |
References
- https://security.gentoo.org/glsa/202107-30Third Party Advisory
- https://xenbits.xenproject.org/xsa/advisory-372.txtVendor Advisory
- https://security.gentoo.org/glsa/202107-30Third Party Advisory
- https://xenbits.xenproject.org/xsa/advisory-372.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-28693?
How severe is CVE-2021-28693?
How do I fix CVE-2021-28693?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-28687HVM soft-reset crashes toolstack libxl requires all data str…5.5
- CVE-2021-28688The fix for XSA-365 includes initialization of pointers such…6.5
- CVE-2021-28689x86: Speculative vulnerabilities with bare (non-shim) 32-bit…5.5
- CVE-2021-28690x86: TSX Async Abort protections not restored after S3 This …6.5
- CVE-2021-28691Guest triggered use-after-free in Linux xen-netback A malici…7.8
- CVE-2021-28692inappropriate x86 IOMMU timeout detection / handling IOMMUs …7.1
- CVE-2021-28694IOMMU page mapping issues on x86 T[his CNA information recor…6.8
- CVE-2021-28695IOMMU page mapping issues on x86 T[his CNA information recor…6.8
- CVE-2021-28696IOMMU page mapping issues on x86 T[his CNA information recor…6.8
- CVE-2021-28697grant table v2 status pages may remain accessible after de-a…7.8
- CVE-2021-28698long running loops in grant table handling In order to prope…5.5
- CVE-2021-28699inadequate grant-v2 status frames array bounds check The v2 …5.5
Are you affected by CVE-2021-28693?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
