Incorrect Resource Transfer Between Spheres in Xen - CVE-2021-28689

 

Incorrect Resource Transfer Between Spheres in Xen - CVE-2021-28689

Published: August 11, 2023


Vulnerability identifier: #VU79453
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28689
CWE-ID: CWE-669
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A local user can gain unauthorized access to sensitive information on the system.


Affected software

Xen
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
xen-tools-domU-debuginfo
xen
xen-debugsource
xen-doc-html
xen-libs-32bit
xen-libs
xen-libs-debuginfo-32bit
xen-libs-debuginfo
xen-tools
xen-tools-debuginfo
xen-tools-domU
xen-devel
xen-tools-xendomains-wait-disk
xen-libs-32bit-debuginfo

How to mitigate CVE-2021-28689

Install updates from vendor's website.

Xen - update to 4.12.0
xen-tools-domU-debuginfo - addressed in versions 4.7.6_28-43.98.1, 4.10.4_40-150000.3.84.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.12.4_30-150100.3.80.1, 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen - addressed in versions 4.7.6_28-43.98.1, 4.10.4_40-150000.3.84.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.12.4_30-150100.3.80.1, 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen-debugsource - addressed in versions 4.7.6_28-43.98.1, 4.10.4_40-150000.3.84.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.12.4_30-150100.3.80.1, 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen-doc-html - addressed in versions 4.7.6_28-43.98.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.14.5_06-150300.3.35.1
xen-libs-32bit - addressed in versions 4.7.6_28-43.98.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.14.5_06-150300.3.35.1
xen-libs - addressed in versions 4.7.6_28-43.98.1, 4.10.4_40-150000.3.84.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.12.4_30-150100.3.80.1, 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen-libs-debuginfo-32bit - addressed in versions 4.7.6_28-43.98.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1
xen-libs-debuginfo - addressed in versions 4.7.6_28-43.98.1, 4.10.4_40-150000.3.84.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.12.4_30-150100.3.80.1, 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen-tools - addressed in versions 4.7.6_28-43.98.1, 4.10.4_40-150000.3.84.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.12.4_30-150100.3.80.1, 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen-tools-debuginfo - addressed in versions 4.7.6_28-43.98.1, 4.10.4_40-150000.3.84.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.12.4_30-150100.3.80.1, 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen-tools-domU - addressed in versions 4.7.6_28-43.98.1, 4.10.4_40-150000.3.84.1, 4.11.4_18-2.54.1, 4.11.4_34-2.83.1, 4.12.4_28-3.77.1, 4.12.4_30-150100.3.80.1, 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen-devel - addressed in versions 4.10.4_40-150000.3.84.1, 4.12.4_28-3.77.1, 4.12.4_30-150100.3.80.1, 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen-tools-xendomains-wait-disk - addressed in versions 4.13.4_16-150200.3.65.1, 4.14.5_06-150300.3.35.1
xen-libs-32bit-debuginfo - update to 4.14.5_06-150300.3.35.1

External References

Related Security Bulletins