CVE-2021-28712 Details
Description
Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary security advantage: if a driver domain gets compromised, it doesn't have the privileges to take over the system. However, a malicious driver domain could try to attack other guests via sending events at a high frequency leading to a Denial of Service in the guest due to trying to service interrupts for elongated amounts of time. There are three affected backends: * blkfront patch 1, CVE-2021-28711 * netfront patch 2, CVE-2021-28712 * hvc_xen (console) patch 3, CVE-2021-28713
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html | CVE | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html | CVE | Third Party Advisory |
| https://www.debian.org/security/2022/dsa-5050 | CVE | Third Party Advisory |
| https://www.debian.org/security/2022/dsa-5096 | CVE | Third Party Advisory |
| https://xenbits.xenproject.org/xsa/advisory-391.txt | CVE | PatchVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html | [email protected] | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html | [email protected] | Third Party Advisory |
| https://www.debian.org/security/2022/dsa-5050 | [email protected] | Third Party Advisory |
| https://www.debian.org/security/2022/dsa-5096 | [email protected] | Third Party Advisory |
| https://xenbits.xenproject.org/xsa/advisory-391.txt | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xen xen | All versions |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 11.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 6, 2022 | Modified Analysis | [email protected] |
| Mar 10, 2022 | CVE Modified | [email protected] |
| Jan 21, 2022 | CVE Modified | [email protected] |
| Jan 18, 2022 | Initial Analysis | [email protected] |