CVE-2021-28713 Information

Description

Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests typically referred to as \driver domains. Running PV backends in driver domains has one primary security advantage: if a driver domain gets compromised it doesn’t have the privileges to take over the system. However a malicious driver domain could try to attack other guests via sending events at a high frequency leading to a Denial of Service in the guest due to trying to service interrupts for elongated amounts of time. There are three affected backends: blkfront patch 1 CVE-2021-28711 netfront patch 2 CVE-2021-28712 hvc_xen (console) patch 3 CVE-2021-28713

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Reference

https://xenbits.xenproject.org/xsa/advisory-391.txt https://www.debian.org/security/2022/dsa-5050 https://www.debian.org/security/2022/dsa-5096 https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

6.5

Share on: