CVE-2021-28700
Summary
| CVE | CVE-2021-28700 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-27 19:15:00 UTC |
| Updated | 2023-11-07 03:32:00 UTC |
| Description | xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured. |
Risk And Classification
Problem Types: CWE-770
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Operating System | Xen | Xen | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 33 Update: xen-4.14.2-3.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| xenbits.xenproject.org/xsa/advisory-383.txt | MISC | xenbits.xenproject.org | |
| [SECURITY] Fedora 33 Update: xen-4.14.2-3.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| FEDORA-2021-081f9bf5d2 | FEDORA | lists.fedoraproject.org | |
| Xen: Multiple Vulnerabilities (GLSA 202208-23) — Gentoo security | GENTOO | security.gentoo.org | |
| Debian -- Security Information -- DSA-4977-1 xen | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 34 Update: xen-4.14.2-3.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 34 Update: xen-4.14.2-3.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 35 Update: xen-4.15.0-6.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 178798 Debian Security Update for xen (DSA 4977-1)
- 184858 Debian Security Update for xen (CVE-2021-28700)
- 281879 Fedora Security Update for xen (FEDORA-2021-4f129cc0c1)
- 281880 Fedora Security Update for xen (FEDORA-2021-d68ed12e46)
- 500801 Alpine Linux Security Update for xen
- 501519 Alpine Linux Security Update for xen
- 501797 Alpine Linux Security Update for xen
- 504544 Alpine Linux Security Update for xen
- 710600 Gentoo Linux Xen Multiple Vulnerabilities (GLSA 202208-23)
- 751074 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2925-1)
- 751083 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:2924-1)
- 751100 OpenSUSE Security Update for xen (openSUSE-SU-2021:2923-1)
- 751111 OpenSUSE Security Update for xen (openSUSE-SU-2021:1236-1)