guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.
[
{
"vendor": "Xen",
"product": "xen",
"versions": [
{
"version": "4.12.x",
"status": "affected"
}
]
},
{
"vendor": "Xen",
"product": "xen",
"versions": [
{
"version": "unspecified",
"lessThan": "4.12",
"status": "unknown",
"versionType": "custom"
},
{
"version": "4.14.x",
"status": "affected",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"version": "next of 4.15.x",
"status": "unaffected",
"lessThan": "unspecified",
"versionType": "custom"
}
]
},
{
"vendor": "Xen",
"product": "xen",
"versions": [
{
"version": "xen-unstable",
"status": "affected"
}
]
},
{
"vendor": "Xen",
"product": "xen",
"versions": [
{
"version": "4.13.x",
"status": "affected"
}
]
}
]
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7ZGWVVRI4XY2XSTBI3XEMWBXPDVX6OT/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PXUI4VMD52CH3T7YXAG3J2JW7ZNN3SXF/
security.gentoo.org/glsa/202402-07
www.debian.org/security/2021/dsa-5017
xenbits.xenproject.org/xsa/advisory-385.txt