CVE-2021-3308
Last modified
CVE-2021-3308 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the system by rebooting itself with MSI or MSI-X capabilities enabled and entries setup. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the system by rebooting itself with MSI or MSI-X capabilities enabled and entries setup. Such reboots will leak any vectors used by the MSI(-X) entries that the guest might had enabled, and hence will lead to vector exhaustion on the system, not allowing further PCI pass through devices to work properly. HVM guests with PCI pass through devices can mount a Denial of Service (DoS) attack affecting the pass through of PCI devices to other guests or the hardware domain. In the latter case, this would affect the entire host.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | >= 4.13.1, <= 4.14.1 |
| Xen | Xen | 4.12.3 |
| Xen | Xen | 4.12.4 |
| Fedoraproject | Fedora | 32 |
References
- http://www.openwall.com/lists/oss-security/2021/01/26/4Mailing List, Patch, Third Party Advisory
- http://xenbits.xen.org/xsa/advisory-360.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/202107-30Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/26/4Mailing List, Patch, Third Party Advisory
- http://xenbits.xen.org/xsa/advisory-360.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/202107-30Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3308?
How severe is CVE-2021-3308?
How do I fix CVE-2021-3308?
Are you affected by CVE-2021-3308?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
