CVE-2021-28690
Summary
| CVE | CVE-2021-28690 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-29 12:15:00 UTC |
| Updated | 2021-09-21 16:13:00 UTC |
| Description | x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https://xenbits.xen.org/xsa/advisory-305.html for details. Mitigating TAA by disabling TSX (the default and preferred option) requires selecting a non-default setting in MSR_TSX_CTRL. This setting isn't restored after S3 suspend. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Xen: Multiple vulnerabilities (GLSA 202107-30) — Gentoo security | GENTOO | security.gentoo.org | |
| xenbits.xenproject.org/xsa/advisory-377.txt | MISC | xenbits.xenproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 178672 Debian Security Update for xen (DSA 4931-1)
- 179562 Debian Security Update for xen (CVE-2021-28690)
- 281644 Fedora Security Update for xen (FEDORA-2021-993693c914)
- 281645 Fedora Security Update for xen (FEDORA-2021-41d4347447)
- 390221 Oracle Managed Virtualization (VM) Server for x86 Security Update for xen (OVMSA-2021-0020)
- 390231 Oracle Managed Virtualization (VM) Server for x86 Security Update for xen (OVMSA-2021-0020)
- 500800 Alpine Linux Security Update for xen
- 501518 Alpine Linux Security Update for xen
- 501796 Alpine Linux Security Update for xen
- 504543 Alpine Linux Security Update for xen
- 710038 Gentoo Linux Xen Multiple vulnerabilities (GLSA 202107-30)
- 751074 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2925-1)
- 751083 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2924-1)
- 751085 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2943-1)
- 751087 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2955-1)
- 751100 OpenSUSE Security Update for xen (openSUSE-SU-2021:2923-1)
- 751103 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2957-1)
- 751111 OpenSUSE Security Update for xen (openSUSE-SU-2021:1236-1)