CVE-2021-28700 — Allocation of Resources Without Limits or Throttling in XEN
Severity
4.9MEDIUMNVD
EPSS
2.1%
top 15.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 27
Latest updateMay 24
Description
xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6
Affected Packages4 packages
Also affects: Debian Linux 11.0, Fedora 33, 34, 35
🔴Vulnerability Details
2GHSA▶
GHSA-whw9-2rv6-633x: xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen↗2022-05-24
OSV▶
CVE-2021-28700: xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen↗2021-08-27
📋Vendor Advisories
1Debian▶
CVE-2021-28700: xen - xen/arm: No memory limit for dom0less domUs The dom0less feature allows an admin...↗2021