Logo
vulnerabilityCVE-2021-28702
Name
CVE-2021-28702
Source
NVD ( link)Debian ( link)
Description
PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform tasks such as legacy USB emulation. If such a device is passed through to a guest, then on guest shutdown the device is not properly deassigned. The IOMMU configuration for these devices which are not properly deassigned ends up pointing to a freed data structure, including the IO Pagetables. Subsequent DMA or interrupts from the device will have unpredictable behaviour, ranging from IOMMU faults to memory corruption.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
xen
Exploitable

Vulnerability Ratings#


7.6
CVSSv31
4.6
CVSSv2

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
master
4.19.5
Not Affected