summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2021-28039
blob: 80e751c48c645f5ba78b073bf8c9013d80f4db15 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
Description: special config may crash when trying to map foreign pages
References:
 https://xenbits.xen.org/xsa/advisory-369.html
 https://lore.kernel.org/lkml/20210304110053.8787-1-jgross@suse.com/
Notes:
 carnil> Commit fixes 9e2369c06c8a18 ("xen: add helpers to allocate
 carnil> unpopulated memory") in 5.9-rc4 (and not backported). To
 carnil> exploit the issue the kernel needs to be configured *with*
 carnil> CONFIG_XEN_UNPOPULATED_ALLOC and *without*
 carnil> CONFIG_XEN_BALLOON_MEMORY_HOTPLUG.
Bugs:
upstream: released (5.12-rc2) [882213990d32fd224340a4533f6318dd152be4b2]
5.10-upstream-stable: released (5.10.21) [9c62adb6e2fda38dc6045a853a6e50b2bbc75d2a]
4.19-upstream-stable: N/A "Vulnerable code introduced later"
4.9-upstream-stable: N/A "Vulnerable code introduced later"
sid: released (5.10.24-1)
4.19-buster-security: N/A "Vulnerable code introduced later"
4.9-stretch-security: N/A "Vulnerable code introduced later"

© 2014-2024 Faster IT GmbH | imprint | privacy policy