cbcvebase.
CVE-2021-28691
published 2021-06-29

CVE-2021-28691: Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
28.4th percentile
Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.46-1 (bookworm)linux 5.10.46-1 (bookworm)
linuxlinux
linuxlinux>= 2ac061ce97f413bfbbdd768f7d2e0fda2e8170df < 6b53db8c4c14b4e7256f058d202908b54a7b85b46b53db8c4c14b4e7256f058d202908b54a7b85b4
linuxlinux>= 2ac061ce97f413bfbbdd768f7d2e0fda2e8170df < caec9bcaeb1a5f03f2d406305355c853af10c13ecaec9bcaeb1a5f03f2d406305355c853af10c13e
linuxlinux>= 2ac061ce97f413bfbbdd768f7d2e0fda2e8170df < 107866a8eb0b664675a260f1ba0655010fac1e08107866a8eb0b664675a260f1ba0655010fac1e08
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 5.11 < 5.12.105.12.10
linuxlinux_kernel>= 5.5 < 5.10.435.10.43
linuxlinux_kernel>= 5.5.0 < 5.12.25.12.2
msrccbl2_kernel_5.10.78.1-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_kernel_5.10.60.1-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.