CVE-2021-28688Improper Initialization in Linux

Severity
6.5MEDIUMNVD
OSV7.8OSV6.7
EPSS
0.1%
top 67.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 6
Latest updateMay 24

Description

The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. The lack of cleanup would result in leaking persistent grants. The leak in turn would prevent fully cleaning up after a respective guest has died, leaving around zombie domains. All Linux versions having the fix for XSA-365 applied are vulner

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages5 packages

CVEListV5linux/linux3.11unspecified+3
debiandebian/linux< linux 5.10.28-1 (bookworm)
Debianlinux/linux_kernel< 5.10.28-1+3
Ubuntulinux/linux_kernel< 4.15.0-143.147+2
NVDlinux/linux_kernel3.115.10.18

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

7
GHSA
GHSA-hqhv-rx9w-cr56: The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values2022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-03-22
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities2021-06-08
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.2021-06-08
OSV
linux-oem-5.10 vulnerabilities2021-05-11

📋Vendor Advisories

5
Ubuntu
Linux kernel vulnerabilities2022-03-22
Ubuntu
Linux kernel vulnerabilities2021-06-08
Ubuntu
Linux kernel (OEM) vulnerabilities2021-05-11
Ubuntu
Linux kernel vulnerabilities2021-05-11
Debian
CVE-2021-28688: linux - The fix for XSA-365 includes initialization of pointers such that subsequent cle...2021
CVE-2021-28688 — Improper Initialization in Linux | cvebase