CVE-2021-27379: High severity xen xapi vulnerability
An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access, and possibly cause a denial of service (host OS crash) or gain privileges. This occurs because a backport missed a flush, and thus IOMMU updates were not always correct. NOTE: this issue exists because of an incomplete fix for CVE-2020-15565.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27379?
CVE-2021-27379 is classified as a high severity vulnerability due to its potential to cause denial of service or privilege escalation.
How do I fix CVE-2021-27379?
To fix CVE-2021-27379, upgrade Xen to a version that is not affected, such as 4.11.4+107-gef32c7afa2-1 or later.
What systems are impacted by CVE-2021-27379?
CVE-2021-27379 affects Xen versions up to and including 4.11.x, specifically on x86 Intel HVM guest OS installations.
Can CVE-2021-27379 lead to a host OS crash?
Yes, CVE-2021-27379 can potentially allow a denial of service condition, leading to a host OS crash.
What causes CVE-2021-27379?
CVE-2021-27379 results from a missed flush in a backport, leading to incorrect IOMMU updates and unintended DMA access.