cbcvebase.
CVE-2021-28688
published 2021-04-06

CVE-2021-28688: The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went…

PriorityP425medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.33%
25.8th percentile
The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. The lack of cleanup would result in leaking persistent grants. The leak in turn would prevent fully cleaning up after a respective guest has died, leaving around zombie domains. All Linux versions having the fix for XSA-365 applied are vulnerable. XSA-365 was classified to affect versions back to at least 3.11.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.10.28-1 (bookworm)linux 5.10.28-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.11 < unspecifiedunspecified
linuxlinux_kernel>= 0 < 5.10.28-15.10.28-1
linuxlinux_kernel>= 0 < 5.10.28-15.10.28-1
linuxlinux_kernel>= 0 < 5.10.28-15.10.28-1
linuxlinux_kernel>= 0 < 5.10.28-15.10.28-1
linuxlinux_kernel>= 0 < 4.15.0-143.1474.15.0-143.147
linuxlinux_kernel>= 0 < 5.4.0-74.835.4.0-74.83
linuxlinux_kernel>= 0 < 4.4.0-222.2554.4.0-222.255
linuxlinux_kernel3.11 – 5.10.18

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.