UBUNTU-CVE-2021-28691
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-28691
UBUNTU-CVE-2021-28691
Summary:
Details: Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.
References: https://ubuntu.com/security/CVE-2021-28691, https://xenbits.xen.org/xsa/advisory-374.html, https://ubuntu.com/security/notices/USN-5015-1, https://ubuntu.com/security/notices/USN-5046-1, https://ubuntu.com/security/notices/USN-5050-1, https://www.cve.org/CVERecord?id=CVE-2021-28691
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
