PT-2021-17910 · Suse · Suse

Julien Grall

·

Published

2021-11-24

·

Updated

2024-02-04

·

CVE-2021-28706

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: No specific software or versions are mentioned in the provided descriptions.
Description: The issue arises when a guest is allowed to have close to 16TiB of memory. It may then issue hypercalls to increase its memory allocation beyond the administrator-established limit due to a calculation done with 32-bit precision, which can overflow. As a result, only the overflowed (and hence small) number gets compared against the established upper bound.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2021-28706
DSA-5017-1
OPENSUSE-SU-2021:1543-1
OPENSUSE-SU-2021:3968-1
OPENSUSE-SU-2021_1543-1
OPENSUSE-SU-2021_3968-1
SUSE-SU-2021:14848-1
SUSE-SU-2021:3813-1
SUSE-SU-2021:3842-1
SUSE-SU-2021:3849-1
SUSE-SU-2021:3851-1
SUSE-SU-2021:3852-1
SUSE-SU-2021:3888-1
SUSE-SU-2021:3968-1
SUSE-SU-2021:3977-1
SUSE-SU-2021_14848-1

Affected Products

Suse