PT-2021-6611 · Xen+1 · Xen+1
Jan Beulich
·
Published
2021-08-27
·
Updated
2022-09-28
·
CVE-2021-28699
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Xen (affected versions not specified)
Description
The issue is related to an inadequate grant-v2 status frames array bounds check in the Xen hypervisor. This allows a guest to potentially cause a denial of service by exploiting the vulnerability in the translation of requests for 32-bit guests on x86. The v2 grant table interface separates grant attributes from grant status, and guests need to retrieve the addresses of the new status tracking table. The translation layer has limited space, and the core function enforces array bounds to be below 8 times the specified value, which can lead to writing past the available space if enough frame numbers are needed.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen