UBUNTU-CVE-2021-28701
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-28701
Summary:
Details: Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, are de-allocated when a guest switches (back) from v2 to v1. Freeing such pages requires that the hypervisor enforce that no parallel request can result in the addition of a mapping of such a page to a guest. That enforcement was missing, allowing guests to retain access to pages that were freed and perhaps re-used for other purposes. Unfortunately, when XSA-379 was being prepared, this similar issue was not noticed.
References: https://ubuntu.com/security/CVE-2021-28701, https://xenbits.xen.org/xsa/advisory-384.html, https://xenbits.xenproject.org/xsa/advisory-384.txt, http://xenbits.xen.org/xsa/advisory-384.html, http://www.openwall.com/lists/oss-security/2021/09/08/2, https://www.cve.org/CVERecord?id=CVE-2021-28701
Affected packages
Package
Name: xen
Purl: pkg:deb/ubuntu/xen?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
