LiveActive security incident?Get immediate response
CVE Record

CVE-2021-28692: inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel wit...

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such commands. In the current implementation in Xen, asynchronous notification of the completion of such commands is not used. Instead, the issuing CPU spin-waits for the completion of the most recently issued command(s). Some of these waiting loops try to apply a timeout to fail overly-slow commands. The course of action upon a perceived timeout actually being detected is inappropriate: - on Intel hardware guests which did not originally cause the timeout may be marked as crashed, - on AMD hardware higher layer callers would not be notified of the issue, making them continue as if the IOMMU operation succeeded.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This Xen issue concerns how x86 hosts handle IOMMU command timeouts. A perceived timeout can lead to incorrect outcomes, including unrelated guests being marked crashed on Intel hardware or failures being hidden on AMD hardware. Business impact is mainly virtualization reliability and availability risk, but the provided sources do not give a CVSS score or confirmed exploitation.

Executive priority

Prioritize review for Xen-based virtualization platforms, especially where guest availability is business-critical. The available evidence supports operational reliability concern, but not confirmed exploitation or quantified severity. Assign vulnerability management follow-up rather than emergency response unless local exposure or vendor guidance raises urgency.

Technical view

Xen spin-waits for IOMMU command completion instead of using asynchronous completion notification. Some wait loops apply timeout handling incorrectly. On Intel systems, guests that did not cause the timeout may be crashed. On AMD systems, upper layers may continue as if an IOMMU operation succeeded because the timeout is not surfaced.

Likely exposure

Exposure is limited to Xen environments listed as affected: Xen 4.11.x, 4.12.x, 4.13.x, 4.14.x, 4.15.x, and xen-unstable on x86 IOMMU-capable hardware. The bundle does not specify whether all configurations are affected or only particular deployment patterns.

Exploitation context

The source bundle does not report active exploitation, and KEV status is false. It describes incorrect timeout handling rather than a public exploit path. Treat exploitability as unclear from the available evidence and focus validation on affected Xen versions and vendor advisory status.

Researcher notes

Key uncertainty is impact scope beyond the described Intel guest crash and AMD silent failure behavior. The bundle provides affected branches but no CVSS, CWE, exploit status, or exact fixed versions. Avoid assuming privilege escalation or data compromise without consulting the linked advisories.

Mitigation direction

  • Review Xen XSA-373 for the vendor’s exact remediation guidance.
  • Review Gentoo GLSA-202107-30 if using Gentoo-packaged Xen.
  • Identify and prioritize affected Xen 4.11.x through 4.15.x hosts.
  • Apply vendor-supported updates or mitigations when confirmed by the advisories.
  • Monitor Xen security channels for follow-up guidance.

Validation and detection

  • Inventory Xen hypervisor versions across virtualization hosts.
  • Confirm whether hosts use x86 Intel or AMD IOMMU hardware.
  • Check whether any systems run xen-unstable or affected stable branches.
  • Review incident logs for unexplained guest crashes or IOMMU timeout messages.
  • Verify remediation status against Xen XSA-373 and Gentoo GLSA-202107-30.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-28692 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Xenxen4.13.xListed
Xenxen4.14.xListed
Xenxen4.15.xListed
Xenxenxen-unstableListed
Xenxen4.12.xListed
Xenxen4.11.xListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.