CVE-2021-3308
Last modified
CVE-2021-3308 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the system by rebooting itself with MSI or MSI-X capabilities enabled and entries setup. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the system by rebooting itself with MSI or MSI-X capabilities enabled and entries setup. Such reboots will leak any vectors used by the MSI(-X) entries that the guest might had enabled, and hence will lead to vector exhaustion on the system, not allowing further PCI pass through devices to work properly. HVM guests with PCI pass through devices can mount a Denial of Service (DoS) attack affecting the pass through of PCI devices to other guests or the hardware domain. In the latter case, this would affect the entire host.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | >= 4.13.1, <= 4.14.1 |
| Xen | Xen | 4.12.3 |
| Xen | Xen | 4.12.4 |
| Fedoraproject | Fedora | 32 |
References
- http://www.openwall.com/lists/oss-security/2021/01/26/4Mailing List, Patch, Third Party Advisory
- http://xenbits.xen.org/xsa/advisory-360.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/202107-30Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/26/4Mailing List, Patch, Third Party Advisory
- http://xenbits.xen.org/xsa/advisory-360.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/202107-30Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3308?
How severe is CVE-2021-3308?
How do I fix CVE-2021-3308?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33074Protection mechanism failure in firmware for some Intel(R) S…4.6
- CVE-2021-33075Race condition in firmware for some Intel(R) Optane(TM) SSD,…4.7
- CVE-2021-33076Improper authentication in firmware for some Intel(R) SSD DC…6.8
- CVE-2021-33077Insufficient control flow management in firmware for some In…6.8
- CVE-2021-33078Race condition within a thread in firmware for some Intel(R)…4.7
- CVE-2021-33079Protection mechanism failure in firmware for some Intel(R) S…4.4
- CVE-2021-33080Exposure of sensitive system information due to uncleared de…6.8
- CVE-2021-33081Protection mechanism failure in firmware for some Intel(R) S…4.4
- CVE-2021-33082Sensitive information in resource not removed before reuse i…4.6
- CVE-2021-33083Improper authentication in firmware for some Intel(R) SSD, I…4.4
- CVE-2021-33084Rejected reason: This is unused.
- CVE-2021-33085Rejected reason: This is unused.
Are you affected by CVE-2021-3308?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
