PT-2021-4229 · Linux · Linux Kernel

Marek Marczykowski-Górecki

·

Published

2021-03-03

·

Updated

2024-03-25

·

CVE-2021-28039

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.9.x through 5.11.3
Description The issue relates to misuse of guest physical addresses when a configuration has CONFIG XEN UNPOPULATED ALLOC but not CONFIG XEN BALLOON MEMORY HOTPLUG, allowing an x86 PV guest OS user to crash a Dom0 or driver domain via a large amount of I/O activity in some less-common configurations. This can lead to a denial of service.
Recommendations For Linux kernel versions 5.9.x through 5.11.3, consider disabling the CONFIG XEN UNPOPULATED ALLOC configuration option or enabling the CONFIG XEN BALLOON MEMORY HOTPLUG option as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2021-04834
CVE-2021-28039
MGASA-2021-0117
MGASA-2021-0152

Affected Products

Linux Kernel