Vulnerability Name: | CVE-2021-26933 (CCN-196829) | ||||||||||||
Assigned: | 2021-02-16 | ||||||||||||
Published: | 2021-02-16 | ||||||||||||
Updated: | 2022-05-27 | ||||||||||||
Summary: | An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as the ones during scrubbing) have reached the memory before handing over the page to a guest. Unfortunately, the operation to clean the cache is happening before checking if the page was scrubbed. Therefore there is no guarantee when all the writes will reach the memory. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-26933 Source: CCN Type: Xen Security Advisory XSA-364 arm: The cache may not be cleaned for newly allocated scrubbed pages Source: MISC Type: Patch, Vendor Advisory http://xenbits.xen.org/xsa/advisory-364.html Source: XF Type: UNKNOWN xen-cve202126933-info-disc(196829) Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-4c819bf1ad Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-47f53a940a Source: DEBIAN Type: Third Party Advisory DSA-4888 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: ![]() | ||||||||||||
BACK |