Vulnerability Name:

CVE-2021-28701 (CCN-208867)

Assigned:2021-09-08
Published:2021-09-08
Updated:2022-10-28
Summary:Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, are de-allocated when a guest switches (back) from v2 to v1. Freeing such pages requires that the hypervisor enforce that no parallel request can result in the addition of a mapping of such a page to a guest. That enforcement was missing, allowing guests to retain access to pages that were freed and perhaps re-used for other purposes. Unfortunately, when XSA-379 was being prepared, this similar issue was not noticed.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
8.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-362
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2021-28701

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20210908 Xen Security Advisory 384 v3 (CVE-2021-28701) - Another race in XENMAPSPACE_grant_table handling

Source: CCN
Type: Xen Security Advisory XSA-384
Another race in XENMAPSPACE_grant_table handling

Source: CONFIRM
Type: Vendor Advisory
http://xenbits.xen.org/xsa/advisory-384.html

Source: XF
Type: UNKNOWN
xen-cve202128701-priv-esc(208867)

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-5a0c7bc619

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-fed53cbc7d

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-11577e5229

Source: GENTOO
Type: Third Party Advisory
GLSA-202208-23

Source: DEBIAN
Type: Third Party Advisory
DSA-4977

Source: MISC
Type: Vendor Advisory
https://xenbits.xenproject.org/xsa/advisory-384.txt

Vulnerable Configuration:Configuration 1:
  • cpe:/o:xen:xen:*:*:*:*:*:*:*:* (Version >= 4.0.0

  • Configuration 2:
  • cpe:/o:debian:debian_linux:11.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:35:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:xensource:xen:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.2:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.5:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.6:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.7:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.8:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.9:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.10:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.11:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.12:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.13:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.14:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.12.3:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.12.4:*:*:*:*:*:*:*
  • OR cpe:/a:xensource:xen:4.13.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7990
    P
    apache-pdfbox-2.0.23-150200.3.6.3 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:8055
    P
    perl-PerlMagick-7.1.0.9-150400.6.18.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7831
    P
    xen-libs-4.17.0_06-150500.1.10 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:51989
    P
    Security update for xen (Important)
    2023-01-26
    oval:org.opensuse.security:def:777
    P
    Security update for webkit2gtk3 (Important)
    2022-09-23
    oval:org.opensuse.security:def:3678
    P
    Security update for liblouis (Important)
    2022-07-06
    oval:org.opensuse.security:def:3488
    P
    flatpak-1.4.2-1.31 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3225
    P
    libopus0-1.1-3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3535
    P
    java-1_8_0-openjdk-1.8.0.222-27.35.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94855
    P
    xen-libs-4.16.0_08-150400.2.12 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94600
    P
    libICE-devel-1.0.9-1.25 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95165
    P
    xen-4.16.0_08-150400.2.12 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:388
    P
    xen-libs-4.16.0_08-150400.2.12 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:95385
    P
    Security update for grub2 (Important)
    2022-06-10
    oval:org.opensuse.security:def:100086
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:6175
    P
    Security update for gnutls (Moderate)
    2022-03-02
    oval:org.opensuse.security:def:102098
    P
    Security update for libsndfile (Important)
    2022-01-11
    oval:org.opensuse.security:def:106752
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:92825
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:8876
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:69966
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:99182
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:106067
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:9826
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:92232
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:9071
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:99377
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:106266
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:92427
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:105677
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:70517
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:99576
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:106465
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:10377
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:92626
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:69767
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:98987
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:105872
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:9627
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:92037
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:99775
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:59570
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:88542
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:126801
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:41886
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:46316
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:33747
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:59828
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:89225
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:127198
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:70319
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:10179
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:69565
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:34005
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:89483
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:9425
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:88225
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:125634
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:24001
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:8678
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:42220
    P
    Security update for xen (Moderate)
    2021-10-21
    oval:org.opensuse.security:def:55256
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:82640
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:29433
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:55959
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:83343
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:30136
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:56079
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:83463
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:30256
    P
    Security update for xen (Moderate)
    2021-10-07
    oval:org.opensuse.security:def:33012
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:84214
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:31278
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:57509
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:86658
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:84672
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:31686
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:58017
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:87476
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:23680
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:51668
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:85742
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:32194
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:58835
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:57101
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:86150
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:111067
    P
    Security update for xen (Moderate)
    2021-09-22
    oval:org.opensuse.security:def:26131
    P
    Security update for xen (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:60366
    P
    Security update for xen (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:34543
    P
    Security update for xen (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:5118
    P
    Security update for xen (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:73699
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:101508
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:102761
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:64767
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:117493
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:99993
    P
    (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:69144
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:107979
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:73889
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:102208
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:111718
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:99143
    P
    (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:66926
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:118523
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:100329
    P
    (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:101313
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:108764
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:75994
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:99415
    P
    (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:5837
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:67264
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:42121
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:100658
    P
    (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:64577
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:109427
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:76332
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:96071
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:1632
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:99678
    P
    (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:69079
    P
    Security update for xen (Moderate)
    2021-09-18
    BACK
    xen xen *
    debian debian linux 11.0
    fedoraproject fedora 33
    fedoraproject fedora 34
    fedoraproject fedora 35
    xensource xen 4.0
    xensource xen 4.1.1
    xensource xen 4.1.2
    xensource xen 4.1
    xensource xen 4.2
    xensource xen 4.5
    xensource xen 4.6
    xensource xen 4.7
    xensource xen 4.8
    xensource xen 4.9
    xensource xen 4.10
    xensource xen 4.11
    xensource xen 4.12
    xensource xen 4.13
    xensource xen 4.14
    xensource xen 4.12.3
    xensource xen 4.12.4
    xensource xen 4.13.1