guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.
References
Link | Resource |
---|---|
https://xenbits.xenproject.org/xsa/advisory-385.txt | Mitigation Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I7ZGWVVRI4XY2XSTBI3XEMWBXPDVX6OT/ | Mailing List Third Party Advisory |
https://www.debian.org/security/2021/dsa-5017 | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXUI4VMD52CH3T7YXAG3J2JW7ZNN3SXF/ | Mailing List Third Party Advisory |
Information
Published : 2021-11-23 17:15
Updated : 2021-12-16 10:42
NVD link : CVE-2021-28706
Mitre link : CVE-2021-28706
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
debian
- debian_linux
xen
- xen
fedoraproject
- fedora