Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-28693

Опубликовано: 30 июн. 2021
Источник: debian
EPSS Низкий

Описание

xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive data is not leaked from the modules, Xen must "scrub" them before handing the page over to the allocator. Unfortunately, it was discovered that modules will not be scrubbed on Arm.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xenfixed4.14.2+25-gb6a8c4f72d-1package
xennot-affectedbusterpackage
xennot-affectedstretchpackage

Примечания

  • https://xenbits.xen.org/xsa/advisory-372.html

EPSS

Процентиль: 19%
0.0006
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive data is not leaked from the modules, Xen must "scrub" them before handing the page over to the allocator. Unfortunately, it was discovered that modules will not be scrubbed on Arm.

CVSS3: 5.5
nvd
больше 4 лет назад

xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive data is not leaked from the modules, Xen must "scrub" them before handing the page over to the allocator. Unfortunately, it was discovered that modules will not be scrubbed on Arm.

github
больше 3 лет назад

xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive data is not leaked from the modules, Xen must "scrub" them before handing the page over to the allocator. Unfortunately, it was discovered that modules will not be scrubbed on Arm.

CVSS3: 5.5
fstec
почти 5 лет назад

Уязвимость гипервизора Xen на Arm, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

suse-cvrf
больше 4 лет назад

Security update for xen

EPSS

Процентиль: 19%
0.0006
Низкий