Логотип exploitDog
bind:CVE-2021-28709
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-28709

Количество 15

Количество 15

ubuntu логотип

CVE-2021-28709

около 4 лет назад

issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). In some cases the hypervisor carries out the requests by splitting them into smaller chunks. Error handling in certain PoD cases has been insufficient in that in particular partial success of some operations was not properly accounted for. There are two code paths affected - page removal (CVE-2021-28705) and insertion of new pages (CVE-2021-28709). (We provide one patch which combines the fix to both issues.)

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2021-28709

около 4 лет назад

issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). In some cases the hypervisor carries out the requests by splitting them into smaller chunks. Error handling in certain PoD cases has been insufficient in that in particular partial success of some operations was not properly accounted for. There are two code paths affected - page removal (CVE-2021-28705) and insertion of new pages (CVE-2021-28709). (We provide one patch which combines the fix to both issues.)

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2021-28709

около 4 лет назад

issues with partially successful P2M updates on x86 T[his CNA informat ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-5rjh-29pm-3mx4

больше 3 лет назад

issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). In some cases the hypervisor carries out the requests by splitting them into smaller chunks. Error handling in certain PoD cases has been insufficient in that in particular partial success of some operations was not properly accounted for. There are two code paths affected - page removal (CVE-2021-28705) and insertion of new pages (CVE-2021-28709). (We provide one patch which combines the fix to both issues.)

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3851-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3813-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3968-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1543-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3968-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3888-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3852-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3849-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3842-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3977-1

около 4 лет назад

Security update for xen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:14848-1

около 4 лет назад

Security update for xen

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-28709

issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). In some cases the hypervisor carries out the requests by splitting them into smaller chunks. Error handling in certain PoD cases has been insufficient in that in particular partial success of some operations was not properly accounted for. There are two code paths affected - page removal (CVE-2021-28705) and insertion of new pages (CVE-2021-28709). (We provide one patch which combines the fix to both issues.)

CVSS3: 7.8
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-28709

issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). In some cases the hypervisor carries out the requests by splitting them into smaller chunks. Error handling in certain PoD cases has been insufficient in that in particular partial success of some operations was not properly accounted for. There are two code paths affected - page removal (CVE-2021-28705) and insertion of new pages (CVE-2021-28709). (We provide one patch which combines the fix to both issues.)

CVSS3: 7.8
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-28709

issues with partially successful P2M updates on x86 T[his CNA informat ...

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-5rjh-29pm-3mx4

issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). In some cases the hypervisor carries out the requests by splitting them into smaller chunks. Error handling in certain PoD cases has been insufficient in that in particular partial success of some operations was not properly accounted for. There are two code paths affected - page removal (CVE-2021-28705) and insertion of new pages (CVE-2021-28709). (We provide one patch which combines the fix to both issues.)

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:3851-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3813-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3968-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1543-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3968-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3888-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3852-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3849-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3842-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3977-1

Security update for xen

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:14848-1

Security update for xen

около 4 лет назад

Уязвимостей на страницу