CVE-2021-28692
Summary
| CVE | CVE-2021-28692 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-30 11:15:00 UTC |
| Updated | 2021-07-12 14:53:00 UTC |
| Description | inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Xen: Multiple vulnerabilities (GLSA 202107-30) — Gentoo security | GENTOO | security.gentoo.org | Mitigation, Third Party Advisory |
| xenbits.xenproject.org/xsa/advisory-373.txt | MISC | xenbits.xenproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 178672 Debian Security Update for xen (DSA 4931-1)
- 180206 Debian Security Update for xen (CVE-2021-28692)
- 281644 Fedora Security Update for xen (FEDORA-2021-993693c914)
- 281645 Fedora Security Update for xen (FEDORA-2021-41d4347447)
- 377778 Citrix XenServer Security Updates (CTX316324)
- 390221 Oracle Managed Virtualization (VM) Server for x86 Security Update for xen (OVMSA-2021-0020)
- 390231 Oracle Managed Virtualization (VM) Server for x86 Security Update for xen (OVMSA-2021-0020)
- 500800 Alpine Linux Security Update for xen
- 501518 Alpine Linux Security Update for xen
- 501796 Alpine Linux Security Update for xen
- 504543 Alpine Linux Security Update for xen
- 710038 Gentoo Linux Xen Multiple vulnerabilities (GLSA 202107-30)
- 751074 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2925-1)
- 751083 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2924-1)
- 751085 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2943-1)
- 751087 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2955-1)
- 751100 OpenSUSE Security Update for xen (openSUSE-SU-2021:2923-1)
- 751103 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2957-1)
- 751111 OpenSUSE Security Update for xen (openSUSE-SU-2021:1236-1)