Lucene search

K
cvelistXENCVELIST:CVE-2021-28706
HistoryNov 24, 2021 - 12:00 a.m.

CVE-2021-28706

2021-11-2400:00:00
XEN
www.cve.org
8
memory limit
hypercalls
overflow
security vulnerability

AI Score

8.7

Confidence

High

EPSS

0.003

Percentile

70.0%

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.

CNA Affected

[
  {
    "vendor": "Xen",
    "product": "xen",
    "versions": [
      {
        "version": "4.12.x",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Xen",
    "product": "xen",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "4.12",
        "status": "unknown",
        "versionType": "custom"
      },
      {
        "version": "4.14.x",
        "status": "affected",
        "lessThan": "unspecified",
        "versionType": "custom"
      },
      {
        "version": "next of 4.15.x",
        "status": "unaffected",
        "lessThan": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Xen",
    "product": "xen",
    "versions": [
      {
        "version": "xen-unstable",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Xen",
    "product": "xen",
    "versions": [
      {
        "version": "4.13.x",
        "status": "affected"
      }
    ]
  }
]

AI Score

8.7

Confidence

High

EPSS

0.003

Percentile

70.0%