CVE-2021-28038
MEDIUMLinux Kernel 2.6.39-5.11.3 - Denial of Service via Netback Driver Memory Allocation Failure
Title source: llmDescription
An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issue exists because of an incomplete fix for CVE-2021-26931.
References (6)
Core 6
Core References
Mailing List, Patch, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2021/03/05/1
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html
Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2021/03/msg00035.html
Patch, Vendor Advisory
http://xenbits.xen.org/xsa/advisory-367.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210409-0001/
Scores
CVSS v3
6.5
EPSS
0.0006
EPSS Percentile
17.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Details
CWE
CWE-770
Status
published
Products (5)
debian/debian_linux
9.0
linux/linux_kernel
5.12 rc1 (2 CPE variants)
linux/linux_kernel
2.6.39 - 4.4.260
netapp/cloud_backup
netapp/solidfire_baseboard_management_controller_firmware
Published
Mar 05, 2021
Tracked Since
Feb 18, 2026