CVE-2021-28698 — Infinite Loop in XEN
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 82.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 27
Latest updateMay 24
Description
long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may create to map grants offered by other domains. In the process of carrying out certain actions, Xen would iterate over all such entries, including ones which aren't in use anymore and some which may have been created but never used. If the number of entries for a given domain is large enough, this iterating of the entire table may tie up a CPU for too …
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Debian Linux 11.0, Fedora 33, 34, 35
🔴Vulnerability Details
2GHSA▶
GHSA-2g34-x978-mw32: long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may cre↗2022-05-24
OSV▶
CVE-2021-28698: long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may cre↗2021-08-27
📋Vendor Advisories
1Debian▶
CVE-2021-28698: xen - long running loops in grant table handling In order to properly monitor resource...↗2021