CVE-2021-28688

Description

The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldnt use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of cleaning up. The lack of cleanup would result in leaking persistent grants. The leak in turn would prevent fully cleaning up after a respective guest has died, leaving around zombie domains. All Linux versions having the fix for XSA-365 applied are vulnerable. XSA-365 was classified to affect versions back to at least 3.11.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.133

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2021:1175-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-4.12.14-16.50.1.x86_64.rpmLinux
SUSE-SU-2021:1175-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-4.12.14-16.50.1.x86_64.rpmLinux
SUSE-SU-2021:1175-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-debuginfo-4.12.14-16.50.1.x86_64.rpmLinux
SUSE-SU-2021:1175-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debuginfo-4.12.14-16.50.1.x86_64.rpmLinux
SUSE-SU-2021:1175-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debugsource-4.12.14-16.50.1.x86_64.rpmLinux
SUSE-SU-2021:1175-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-devel-4.12.14-16.50.1.x86_64.rpmLinux
SUSE-SU-2021:1175-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-devel-azure-4.12.14-16.50.1.noarch.rpmLinux
SUSE-SU-2021:1175-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-source-azure-4.12.14-16.50.1.noarch.rpmLinux
SUSE-SU-2021:1175-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-syms-azure-4.12.14-16.50.1.x86_64.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-default-4.12.14-122.66.2.x86_64.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-default-base-4.12.14-122.66.2.x86_64.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-default-base-debuginfo-4.12.14-122.66.2.x86_64.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-default-debuginfo-4.12.14-122.66.2.x86_64.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-default-debugsource-4.12.14-122.66.2.x86_64.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-default-devel-4.12.14-122.66.2.x86_64.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-default-devel-debuginfo-4.12.14-122.66.2.x86_64.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-devel-4.12.14-122.66.2.noarch.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-macros-4.12.14-122.66.2.noarch.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-source-4.12.14-122.66.2.noarch.rpmLinux
SUSE-SU-2021:1210-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-syms-4.12.14-122.66.2.x86_64.rpmLinux
Kernel-uek update (ELSA-2021-9215) kernel-uek-4.1.12-124.50.2.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2021-9215) kernel-uek-debug-4.1.12-124.50.2.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2021-9215) kernel-uek-debug-devel-4.1.12-124.50.2.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2021-9215) kernel-uek-devel-4.1.12-124.50.2.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2021-9215) kernel-uek-doc-4.1.12-124.50.2.el7uek.noarch.rpmLinux
Kernel-uek-firmware update (ELSA-2021-9215) kernel-uek-firmware-4.1.12-124.50.2.el7uek.noarch.rpmLinux
Linux kernel (USN-4946-1) linux-image-kvm_4.15.0.1091.87_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-generic_4.15.0.143.130_i386.debLinux
Linux kernel (USN-4946-1) linux-image-generic_4.15.0.143.130_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-virtual_4.15.0.143.130_i386.debLinux
Linux kernel (USN-4946-1) linux-image-virtual_4.15.0.143.130_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-dell300x_4.15.0.1018.20_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-lowlatency_4.15.0.143.130_i386.debLinux
Linux kernel (USN-4946-1) linux-image-lowlatency_4.15.0.143.130_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-aws-lts-18.04_4.15.0.1102.105_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-gcp-lts-18.04_4.15.0.1099.117_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-1091-kvm_4.15.0-1091.93_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-1099-gcp_4.15.0-1099.112_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-1102-aws_4.15.0-1102.109_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-azure-lts-18.04_4.15.0.1114.87_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-oracle-lts-18.04_4.15.0.1071.81_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-1114-azure_4.15.0-1114.127_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-1071-oracle_4.15.0-1071.79_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-143-generic_4.15.0-143.147_i386.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-143-generic_4.15.0-143.147_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-1018-dell300x_4.15.0-1018.22_amd64.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-143-lowlatency_4.15.0-143.147_i386.debLinux
Linux kernel (USN-4946-1) linux-image-4.15.0-143-lowlatency_4.15.0-143.147_amd64.debLinux
Linux kernel for OEM systems (USN-4948-1) linux-image-oem-20.04b_5.10.0.1026.27_amd64.debLinux
Linux kernel for OEM systems (USN-4948-1) linux-image-5.10.0-1026-oem_5.10.0-1026.27_amd64.debLinux
Kernel-uek update (ELSA-2021-9220) kernel-uek-5.4.17-2102.201.3.el8uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2021-9220) kernel-uek-debug-5.4.17-2102.201.3.el8uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2021-9220) kernel-uek-debug-devel-5.4.17-2102.201.3.el8uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2021-9220) kernel-uek-devel-5.4.17-2102.201.3.el8uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2021-9220) kernel-uek-doc-5.4.17-2102.201.3.el8uek.noarch.rpmLinux
Kernel-uek update (ELSA-2021-9222) kernel-uek-4.14.35-2047.503.1.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2021-9222) kernel-uek-debug-4.14.35-2047.503.1.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2021-9222) kernel-uek-debug-devel-4.14.35-2047.503.1.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2021-9222) kernel-uek-devel-4.14.35-2047.503.1.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2021-9222) kernel-uek-doc-4.14.35-2047.503.1.el7uek.noarch.rpmLinux
Kernel-uek-tools update (ELSA-2021-9222) kernel-uek-tools-4.14.35-2047.503.1.el7uek.x86_64.rpmLinux
Linux kernel (USN-4982-1) linux-image-aws_5.4.0.1049.31_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-aws_5.4.0.1049.50_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-gcp_5.4.0.1044.31_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-gcp_5.4.0.1044.53_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-gke_5.4.0.1044.53_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-kvm_5.4.0.1040.38_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-oem_5.4.0.74.77_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-oem_5.4.0.74.83~18.04.67_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-azure_5.4.0.1048.27_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-azure_5.4.0.1048.46_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-gkeop_5.4.0.1016.19_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-oracle_5.4.0.1046.45_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-oracle_5.4.0.1046.50~18.04.28_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-generic_5.4.0.74.77_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-gke-5.4_5.4.0.1044.53_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-gke-5.4_5.4.0.1044.46~18.04.10_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-virtual_5.4.0.74.77_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-oem-osp1_5.4.0.74.77_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-oem-osp1_5.4.0.74.83~18.04.67_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-gkeop-5.4_5.4.0.1016.19_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-gkeop-5.4_5.4.0.1016.17~18.04.17_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-lowlatency_5.4.0.74.77_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1040-kvm_5.4.0-1040.41_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1044-gcp_5.4.0-1044.47_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1044-gcp_5.4.0-1044.47~18.04.2_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1044-gke_5.4.0-1044.46_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1044-gke_5.4.0-1044.46~18.04.1_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1049-aws_5.4.0-1049.51_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1049-aws_5.4.0-1049.51~18.04.1_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1016-gkeop_5.4.0-1016.17_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1016-gkeop_5.4.0-1016.17~18.04.1_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1048-azure_5.4.0-1048.50_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1048-azure_5.4.0-1048.50~18.04.1_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-74-generic_5.4.0-74.83_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-74-generic_5.4.0-74.83~18.04.1_i386.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-74-generic_5.4.0-74.83~18.04.1_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1046-oracle_5.4.0-1046.50_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-1046-oracle_5.4.0-1046.50~18.04.2_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-generic-hwe-18.04_5.4.0.74.83~18.04.67_i386.debLinux
Linux kernel (USN-4982-1) linux-image-generic-hwe-18.04_5.4.0.74.83~18.04.67_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-virtual-hwe-18.04_5.4.0.74.77_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-virtual-hwe-18.04_5.4.0.74.83~18.04.67_i386.debLinux
Linux kernel (USN-4982-1) linux-image-virtual-hwe-18.04_5.4.0.74.83~18.04.67_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-74-lowlatency_5.4.0-74.83_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-74-lowlatency_5.4.0-74.83~18.04.1_i386.debLinux
Linux kernel (USN-4982-1) linux-image-5.4.0-74-lowlatency_5.4.0-74.83~18.04.1_amd64.debLinux
Linux kernel (USN-4982-1) linux-image-lowlatency-hwe-18.04_5.4.0.74.83~18.04.67_i386.debLinux
Linux kernel (USN-4982-1) linux-image-lowlatency-hwe-18.04_5.4.0.74.83~18.04.67_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-aws_5.8.0.1035.37_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-gcp_5.8.0.1032.32_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-gke_5.8.0.1032.32_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-kvm_5.8.0.1028.30_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-azure_5.8.0.1033.33_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-oracle_5.8.0.1031.30_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-generic_5.8.0.55.60_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-virtual_5.8.0.55.60_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-lowlatency_5.8.0.55.60_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-5.8.0-1028-kvm_5.8.0-1028.30_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-5.8.0-1032-gcp_5.8.0-1032.34_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-5.8.0-1035-aws_5.8.0-1035.37_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-5.8.0-1033-azure_5.8.0-1033.35_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-5.8.0-55-generic_5.8.0-55.62_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-5.8.0-55-generic_5.8.0-55.62~20.04.1_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-5.8.0-1031-oracle_5.8.0-1031.32_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-generic-hwe-20.04_5.8.0.55.62~20.04.39_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-virtual-hwe-20.04_5.8.0.55.62~20.04.39_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-5.8.0-55-lowlatency_5.8.0-55.62_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-5.8.0-55-lowlatency_5.8.0-55.62~20.04.1_amd64.debLinux
Linux kernel (USN-4984-1) linux-image-lowlatency-hwe-20.04_5.8.0.55.62~20.04.39_amd64.debLinux
kernel Security Update (ALAS-2021-1627) kernel-livepatch-4.14.231-173.360-1.0-0.amzn2.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234