CVE-2021-28693
- EPSS 0.06%
- Published 30.06.2021 11:15:08
- Last modified 21.11.2024 06:00:09
xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive data is not leaked from the modules, Xen must "scrub...
CVE-2021-28690
- EPSS 0.36%
- Published 29.06.2021 12:15:08
- Last modified 21.11.2024 06:00:09
x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https://xenbits.xen.org/xsa/advisory-305.html for details. Mitigating TAA by disabling TSX (the default an...
CVE-2021-28687
- EPSS 0.05%
- Published 11.06.2021 15:15:11
- Last modified 21.11.2024 06:00:08
HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized before use and disposed of afterwards by calling a specific set of functions. Many internal data structures also require this ini...
CVE-2021-28689
- EPSS 0.08%
- Published 11.06.2021 15:15:11
- Last modified 21.11.2024 06:00:08
x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed, this area of the i386 architecture was rarely used, which is why Xen was able to use it to implement...
CVE-2021-26313
- EPSS 0.08%
- Published 09.06.2021 12:15:07
- Last modified 21.11.2024 05:56:04
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.
CVE-2021-26314
- EPSS 0.1%
- Published 09.06.2021 12:15:07
- Last modified 21.11.2024 05:56:04
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result...
CVE-2021-28039
- EPSS 0.14%
- Published 05.03.2021 18:15:13
- Last modified 21.11.2024 05:59:01
An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest...
CVE-2021-27379
- EPSS 0.07%
- Published 18.02.2021 17:15:15
- Last modified 21.11.2024 05:57:52
An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access, and possibly cause a denial of service (host OS crash) or gain privileges. This occurs because a backport missed a flush...
CVE-2021-26933
- EPSS 0.08%
- Published 17.02.2021 02:15:13
- Last modified 21.11.2024 05:57:04
An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as the ones during scrubbing) have reached the memory ...
CVE-2021-3308
- EPSS 0.06%
- Published 26.01.2021 20:15:12
- Last modified 21.11.2024 06:21:15
An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the system by rebooting itself with MSI or MSI-X capabilities enabled and en...