CVE-2021-28691

Executive Summary

A malicious or buggy Xen PV frontend can send a malformed packet that forces the Linux netback to disable the interface and terminate the receive kernel thread for queue 0. When the backend is later destroyed, kthread_stop is invoked on a stale pointer, causing a use‑after‑free in the netback driver. This flaw can crash the host or potentially allow arbitrary code execution from a guest.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2021-06-29T12:15:08.543 - Last Modified: 2026-08-26T17:57:08.287

Original Description: Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.

"Better than a thousand hollow words, is one word that brings peace."

— Buddha
Source: NVD