CVE-2021-4440·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: x86/xen: Drop USERGS_SYSRET64 paravirt call commit afd30525a659ac0ae0904f0cb4a2ca75522c3123 upstream. USERGS_SYSRET64 is used to return from a syscall via SYSRET, but a Xen PV guest will nevertheless use the IRET hypercall, as there is no sysret PV hypercall defined. So instead of testing all the prerequisites for doing a sysret and then mangling the stack for Xen PV again for doing an iret just use the iret exit from the beginning. This can easily be done via an ALTERNATIVE like it is done for the sysenter compat case already. It should be noted that this drops the optimization in Xen for not restoring a few registers when returning to user mode, but it seems as if the saved instructions in the kernel more than compensate for this drop (a kernel build in a Xen PV guest was slightly faster with this patch applied). While at it remove the stale sysret32 remnants. [ pawan: Brad Spengler and Salvatore Bonaccorso <carnil@debian.org> reported a problem with the 5.10 backport commit edc702b4a820 ("x86/entry_64: Add VERW just before userspace transition"). When CONFIG_PARAVIRT_XXL=y, CLEAR_CPU_BUFFERS is not executed in syscall_return_via_sysret path as USERGS_SYSRET64 is runtime patched to: .cpu_usergs_sysret64 = { 0x0f, 0x01, 0xf8, 0x48, 0x0f, 0x07 }, // swapgs; sysretq which is missing CLEAR_CPU_BUFFERS. It turns out dropping USERGS_SYSRET64 simplifies the code, allowing CLEAR_CPU_BUFFERS to be explicitly added to syscall_return_via_sysret path. Below is with CONFIG_PARAVIRT_XXL=y and this patch applied: syscall_return_via_sysret: ... <+342>: swapgs <+345>: xchg %ax,%ax <+347>: verw -0x1a2(%rip) <------ <+354>: sysretq ]
- Severity
- high
- Software
- Kernel
- Fixed in
- 5.10.218
- Published
- 2024-06-25
Affected versions
From: 5.10.215
Until: 5.10.218
Fixed in: 5.10.218
How to fix this CVE
Update your Linux kernel to version 5.10.218 or later to address this x86/Xen paravirtualization vulnerability. This patch simplifies the syscall return path and ensures proper CPU buffer clearing during userspace transitions, eliminating a security gap in Xen PV guest configurations. Systems running kernel versions 5.10.215 through 5.10.217 should prioritize this update.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your kernel version with `uname -r` and compare against the affected range 5.10.215-5.10.217
- Step 2: Verify if your system is running Xen PV guest mode by checking `cat /proc/xen/capabilities` for 'control_d' entry
- Step 3: Review kernel logs for CPU buffer clearing failures or unusual syscall return behavior using `dmesg | grep -i 'sysret\|verw\|buffer'`
- Step 4: After patching, verify the new kernel is loaded with `uname -r` and confirm it reports version 5.10.218 or higher
FAQ
What is CVE-2021-4440?
CVE-2021-4440 is a high-severity vulnerability in the Linux kernel affecting the x86 syscall return path on Xen PV guests, where CPU buffer clearing (VERW instruction) was not properly executed before returning to userspace, potentially exposing sensitive kernel data through microarchitectural side-channels.
Is CVE-2021-4440 being actively exploited?
No, there is no evidence of active exploitation or public exploits available for CVE-2021-4440 according to CISA's Known Exploited Vulnerabilities catalog.
What versions of Kernel are affected by CVE-2021-4440?
Kernel versions 5.10.215 through 5.10.217 on x86 systems with CONFIG_PARAVIRT_XXL enabled and running as Xen PV guests are affected.
How do I check if my server is vulnerable to CVE-2021-4440?
Run `uname -r` to check your kernel version and `cat /proc/xen/capabilities` to verify Xen PV guest mode. If your version is between 5.10.215-5.10.217 and you're in a Xen environment, you are vulnerable.
Does Defensia detect CVE-2021-4440?
Yes — Defensia's CVE advisory scanner compares installed kernel package versions against the NVD database. If kernel is installed on a monitored server, CVE-2021-4440 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-4440. Free for 1 server.
Get started free