PT-2021-6611 · Xen+1 · Xen+1

Jan Beulich

·

Published

2021-08-27

·

Updated

2022-09-28

·

CVE-2021-28699

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue is related to an inadequate grant-v2 status frames array bounds check in the Xen hypervisor. This allows a guest to potentially cause a denial of service by exploiting the vulnerability in the translation of requests for 32-bit guests on x86. The v2 grant table interface separates grant attributes from grant status, and guests need to retrieve the addresses of the new status tracking table. The translation layer has limited space, and the core function enforces array bounds to be below 8 times the specified value, which can lead to writing past the available space if enough frame numbers are needed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01887
CVE-2021-28699
DSA-4977-1
OPENSUSE-SU-2021:1236-1
OPENSUSE-SU-2021:2923-1
OPENSUSE-SU-2021_1236-1
OPENSUSE-SU-2021_2923-1
SUSE-SU-2021:2922-1
SUSE-SU-2021:2923-1
SUSE-SU-2021:2924-1
SUSE-SU-2021:2925-1
SUSE-SU-2021:2943-1
SUSE-SU-2021:2955-1
SUSE-SU-2021:2957-1

Affected Products

Suse
Xen