CVE-2021-28713: Medium severity xen xapi vulnerability
Last updated 25 April 2025
Other sources
Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen offers the ability to run PV backends in regular unprivileged guests, typically referred to as "driver domains". Running PV backends in driver domains has one primary security advantage: if a driver domain gets compromised, it doesn't have the privileges to take over the system. However, a malicious driver domain could try to attack other guests via sending events at a high frequency leading to a Denial of Service in the guest due to trying to service interrupts for elongated amounts of time. There are three affected backends: blkfront patch 1, CVE-2021-28711 netfront patch 2, CVE-2021-28712 hvcxen (console) patch 3, CVE-2021-28713
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28713?
CVE-2021-28713 has a high severity rating which indicates it poses a significant risk of denial of service (DoS) to virtual guests.
How do I fix CVE-2021-28713?
To fix CVE-2021-28713, it is recommended to upgrade to the latest patched versions of the affected Linux packages.
What impact does CVE-2021-28713 have on affected systems?
CVE-2021-28713 can lead to a denial of service condition by allowing rogue backends to generate high frequency events.
Which software is affected by CVE-2021-28713?
CVE-2021-28713 affects various versions of Debian Linux and Xen hypervisor as detailed in the vulnerability announcement.
Is CVE-2021-28713 exploitable?
Yes, CVE-2021-28713 is exploitable in configurations that allow unprivileged guests to run PV backends.