CVE-2021-28706

HIGH

Xen 3.2-4.12 - Memory Limit Bypass via 32-bit Overflow

Title source: llm
STIX 2.1

Description

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.

Scores

CVSS v3 8.6
EPSS 0.0015
EPSS Percentile 35.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (4)
debian/debian_linux 11.0
fedoraproject/fedora 34
fedoraproject/fedora 35
xen/xen 3.2 - 4.12
Published Nov 24, 2021
Tracked Since Feb 18, 2026