Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-28706

Опубликовано: 24 нояб. 2021
Источник: nvd
CVSS3: 8.6
CVSS2: 7.8
EPSS Низкий

Описание

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*
Версия от 3.2 (включая) до 4.12 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00155
Низкий

8.6 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 4 лет назад

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.

CVSS3: 8.6
debian
около 4 лет назад

guests may exceed their designated memory limit When a guest is permit ...

CVSS3: 8.6
github
больше 3 лет назад

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.

suse-cvrf
около 4 лет назад

Security update for xen

suse-cvrf
около 4 лет назад

Security update for xen

EPSS

Процентиль: 37%
0.00155
Низкий

8.6 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-770