First published: Fri Aug 27 2021(Updated: )
xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured.
Credit: security@xen.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/xen | 4.11.4+107-gef32c7afa2-1 4.14.6-1 4.14.5+94-ge49571868d-1 4.17.1+2-gb773c48e36-1 4.17.2+55-g0b56bed864-1 | |
Xen xen-unstable | >=4.12.0 | |
Fedora | =33 | |
Fedora | =34 | |
Fedora | =35 | |
Debian | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28700 is considered a medium severity vulnerability due to the potential for unprivileged domains to allocate excessive memory.
To fix CVE-2021-28700, ensure you update to the latest versions of Xen, such as 4.11.4+107-gef32c7afa2-1 or higher.
CVE-2021-28700 affects Xen versions starting from 4.12.0 and includes specific versions up to 4.17.2+55-g0b56bed864-1.
Leaving CVE-2021-28700 unpatched can allow unprivileged domains to consume unlimited memory, potentially leading to Denial of Service attacks.
CVE-2021-28700 primarily affects Xen running on Debian and Fedora operating systems.