imPC@ndo IT

Tracker / CVE-2021-28039

CVE-2021-28039

Medium 6.5

An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG.

Affected products and versions

linux linux_kernel · 5.9.0 → 5.11.3
netapp cloud_backup
netapp solidfire_baseboard_management_controller_firmware
xen xen

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References