CVE-2021-28038: Medium severity linux kernel vulnerability
An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issue exists because of an incomplete fix for CVE-2021-26931.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28038?
CVE-2021-28038 has been classified as a high severity vulnerability due to its potential to cause denial of service in the host operating system.
How do I fix CVE-2021-28038?
To fix CVE-2021-28038, upgrade to the recommended patched versions of the Linux kernel including 5.10.223-1 or later.
Which systems are affected by CVE-2021-28038?
CVE-2021-28038 affects various versions of the Linux kernel from 2.6.39 to 5.11.3, especially those used in Xen PV environments.
What types of attacks can exploit CVE-2021-28038?
CVE-2021-28038 can be exploited by attackers to trigger a denial of service condition in the host OS through specific error handling in the netback driver.
Is there a workaround for CVE-2021-28038?
Currently, the recommended mitigation for CVE-2021-28038 is to apply the available updates or patches for the Linux kernel rather than relying on a workaround.