CVE-2021-28700Allocation of Resources Without Limits or Throttling in XEN

Severity
4.9MEDIUMNVD
EPSS
2.1%
top 15.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27
Latest updateMay 24

Description

xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages4 packages

CVEListV5xen/xen4.13.xunspecified+1
debiandebian/xen< xen 4.14.3-1 (bookworm)
Debianxen/xen< 4.14.3-1~deb11u1+3
NVDxen/xen

Also affects: Debian Linux 11.0, Fedora 33, 34, 35

🔴Vulnerability Details

2
GHSA
GHSA-whw9-2rv6-633x: xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen2022-05-24
OSV
CVE-2021-28700: xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen2021-08-27

📋Vendor Advisories

1
Debian
CVE-2021-28700: xen - xen/arm: No memory limit for dom0less domUs The dom0less feature allows an admin...2021