cbcvebase.
CVE-2021-28692
published 2021-06-30

CVE-2021-28692: inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.28%
20.4th percentile
inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.14.2+25-gb6a8c4f72d-1 (bookworm)xen 4.14.2+25-gb6a8c4f72d-1 (bookworm)
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen>= 0 < 4.14.2+25-gb6a8c4f72d-14.14.2+25-gb6a8c4f72d-1
xenxen>= 0 < 4.14.2+25-gb6a8c4f72d-14.14.2+25-gb6a8c4f72d-1
xenxen>= 0 < 4.14.2+25-gb6a8c4f72d-14.14.2+25-gb6a8c4f72d-1
xenxen>= 0 < 4.14.2+25-gb6a8c4f72d-14.14.2+25-gb6a8c4f72d-1
xenxen>= 3.2.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.05.6MEDIUMAV:L/AC:L/Au:N/C:P/I:N/A:C
osv7.1HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.