CVE-2021-28706
Dashboard / Vulnerabilities / CVE-2021-28706
CVE-2021-28706
Summary:
Details: guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.
References: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7ZGWVVRI4XY2XSTBI3XEMWBXPDVX6OT/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PXUI4VMD52CH3T7YXAG3J2JW7ZNN3SXF/, https://security.gentoo.org/glsa/202402-07, https://www.debian.org/security/2021/dsa-5017, https://xenbits.xenproject.org/xsa/advisory-385.txt
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
