CVE-2021-28706
Summary
| CVE | CVE-2021-28706 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-24 01:15:00 UTC |
| Updated | 2024-02-04 08:15:00 UTC |
| Description | guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound. |
NVD Known Affected Configurations (CPE 2.3)
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 178928 Debian Security Update for xen (DSA 5017-1)
- 184152 Debian Security Update for xen (CVE-2021-28706)
- 282100 Fedora Security Update for xen (FEDORA-2021-2b3a2de94f)
- 282136 Fedora Security Update for xen (FEDORA-2021-03645e9807)
- 390253 Oracle Managed Virtualization (VM) Server for x86 Security Update for xen (OVMSA-2022-0004)
- 390255 Oracle Managed Virtualization (VM) Server for x86 Security Update for xen (OVMSA-2022-0003)
- 500805 Alpine Linux Security Update for xen
- 500806 Alpine Linux Security Update for xen
- 501523 Alpine Linux Security Update for xen
- 501801 Alpine Linux Security Update for xen
- 710858 Gentoo Linux Xen Multiple Vulnerabilities (GLSA 202402-07)
- 751411 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:3852-1)
- 751414 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:3851-1)
- 751417 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:3842-1)
- 751422 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:3849-1)
- 751454 OpenSUSE Security Update for xen (openSUSE-SU-2021:1543-1)
- 751474 OpenSUSE Security Update for xen (openSUSE-SU-2021:3968-1)
- 751477 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2021:3977-1)