cbcvebase.
CVE-2021-28038
published 2021-03-05

CVE-2021-28038: An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such…

PriorityP426medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.71%
49.9th percentile
An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issue exists because of an incomplete fix for CVE-2021-26931.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.10.24-1 (bookworm)linux 5.10.24-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.24-15.10.24-1
linuxlinux_kernel>= 0 < 5.10.24-15.10.24-1
linuxlinux_kernel>= 0 < 5.10.24-15.10.24-1
linuxlinux_kernel>= 0 < 5.10.24-15.10.24-1
linuxlinux_kernel>= 0 < 4.4.0-208.2404.4.0-208.240
linuxlinux_kernel>= 0 < 4.15.0-143.1474.15.0-143.147
linuxlinux_kernel>= 0 < 5.4.0-73.825.4.0-73.82
linuxlinux_kernel>= 2.6.39 < 4.4.2604.4.260
linuxlinux_kernel>= 4.10.0 < 4.14.2244.14.224
linuxlinux_kernel>= 4.15.0 < 4.19.1794.19.179
linuxlinux_kernel>= 4.20.0 < 5.4.1035.4.103
linuxlinux_kernel>= 4.5.0 < 4.9.2604.9.260
linuxlinux_kernel>= 5.10.0 < 5.10.215.10.21
linuxlinux_kernel>= 5.11.0 < 5.11.45.11.4

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.7MEDIUM
vendor_ubuntu6.7MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.