CVE-2021-28690
Published: 29 June 2021
x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https://xenbits.xen.org/xsa/advisory-305.html for details. Mitigating TAA by disabling TSX (the default and preferred option) requires selecting a non-default setting in MSR_TSX_CTRL. This setting isn't restored after S3 suspend.
Priority
CVSS 3 base score: 6.5
Notes
Author | Note |
---|---|
mdeslaur | hypervisor packages are in universe. For issues in the hypervisor, add appropriate tags to each section, ex: Tags_xen: universe-binary |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28690
- https://xenbits.xen.org/xsa/advisory-377.html
- NVD
- Launchpad
- Debian