Lucene search

K
cvelistMitreCVELIST:CVE-2021-28039
HistoryMar 05, 2021 - 12:00 a.m.

CVE-2021-28039

2021-03-0500:00:00
mitre
www.cve.org
6
linux kernel
xen
pv guest os
dom0
driver domain
i/o activity
guest physical addresses
memory hotplug

AI Score

6.4

Confidence

High

EPSS

0

Percentile

5.1%

An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG.

AI Score

6.4

Confidence

High

EPSS

0

Percentile

5.1%