x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vulnerability. Please see https://xenbits.xen.org/xsa/advisory-305.html for details. Mitigating TAA by disabling TSX (the default and preferred option) requires selecting a non-default setting in MSR_TSX_CTRL. This setting isn't restored after S3 suspend.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Mar 26, 2024 | Jun 29, 2021 |
| Debian | — | Upgrade xen | Jun 17, 2021 | Jun 17, 2021 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Jul 13, 2021 | Jun 29, 2021 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-tools-xendomains-wait-diskUpgrade xen-tools-domUUpgrade xen-develUpgrade xen-doc-htmlUpgrade xenUpgrade xen-kmp-defaultUpgrade xen-toolsUpgrade xen-libsUpgrade xen-libs-32bit | Sep 3, 2021 | Jun 29, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub