CVE-2021-28696
Last modified
CVE-2021-28696 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typically device specific ACPI properties, they can also be specified to apply to a range of devices, or even all devices. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these are typically device specific ACPI properties, they can also be specified to apply to a range of devices, or even all devices. On all systems with such regions Xen failed to prevent guests from undoing/replacing such mappings (CVE-2021-28694). On AMD systems, where a discontinuous range is specified by firmware, the supposedly-excluded middle range will also be identity-mapped (CVE-2021-28695). Further, on AMD systems, upon de-assigment of a physical device from a guest, the identity mappings would be left in place, allowing a guest continued access to ranges of memory which it shouldn't have access to anymore (CVE-2021-28696).
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | All versions |
| Fedoraproject | Fedora | 33 |
| Fedoraproject | Fedora | 34 |
| Fedoraproject | Fedora | 35 |
| Debian | Debian Linux | 11.0 |
References
- http://www.openwall.com/lists/oss-security/2021/09/01/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/01/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/01/6Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202208-23Third Party Advisory
- https://www.debian.org/security/2021/dsa-4977Third Party Advisory
- https://xenbits.xenproject.org/xsa/advisory-378.txtVendor Advisory
- http://www.openwall.com/lists/oss-security/2021/09/01/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/01/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/01/6Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202208-23Third Party Advisory
- https://www.debian.org/security/2021/dsa-4977Third Party Advisory
- https://xenbits.xenproject.org/xsa/advisory-378.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-28696?
How severe is CVE-2021-28696?
How do I fix CVE-2021-28696?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-28690x86: TSX Async Abort protections not restored after S3 This …6.5
- CVE-2021-28691Guest triggered use-after-free in Linux xen-netback A malici…7.8
- CVE-2021-28692inappropriate x86 IOMMU timeout detection / handling IOMMUs …7.1
- CVE-2021-28693xen/arm: Boot modules are not scrubbed The bootloader will l…5.5
- CVE-2021-28694IOMMU page mapping issues on x86 T[his CNA information recor…6.8
- CVE-2021-28695IOMMU page mapping issues on x86 T[his CNA information recor…6.8
- CVE-2021-28697grant table v2 status pages may remain accessible after de-a…7.8
- CVE-2021-28698long running loops in grant table handling In order to prope…5.5
- CVE-2021-28699inadequate grant-v2 status frames array bounds check The v2 …5.5
- CVE-2021-28700xen/arm: No memory limit for dom0less domUs The dom0less fea…4.9
- CVE-2021-28701Another race in XENMAPSPACE_grant_table handling Guests are …7.8
- CVE-2021-28702PCI devices with RMRRs not deassigned correctly Certain PCI …7.6
Are you affected by CVE-2021-28696?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
