PT-2021-6824 · Xen+1 · Xen+1

Julien Grall

·

Published

2021-08-27

·

Updated

2022-10-28

·

CVE-2021-28700

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue is related to the dom0less feature of the Xen hypervisor, which allows administrators to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit for these domains is not set, allowing a domain to allocate memory beyond what an administrator originally configured. This can be exploited by a remote attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02249
CVE-2021-28700
DSA-4977-1
OPENSUSE-SU-2021:1236-1
OPENSUSE-SU-2021:2923-1
OPENSUSE-SU-2021_1236-1
OPENSUSE-SU-2021_2923-1
SUSE-SU-2021:2922-1
SUSE-SU-2021:2923-1
SUSE-SU-2021:2924-1
SUSE-SU-2021:2925-1

Affected Products

Suse
Xen