CVE Database
/

CVE-2021-28693

Back to search

CVE-2021-28693

Published: Jun 30, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary area before they are copied by Xen to each domain memory. To ensure sensitive data is not leaked from the modules, Xen must "scrub" them before handing the page over to the allocator. Unfortunately, it was discovered that modules will not be scrubbed on Arm.

VendorProductVersions

Xen

xen

affected
4.15.x

Xen

xen

unknown
unspecified - < 4.12
affected
4.13.x - < unspecified
unaffected
next of 4.14.x - < unspecified

Xen

xen

affected
xen-unstable

Xen

xen

affected
4.12.x

References

GLSA-202107-30
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now