An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG.
2021-03-05T18:15:13.190
2024-11-21T05:59:01.627
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | ≤ 5.11.3 | Yes |
Operating System | xen | xen | - | Yes |
Application | netapp | cloud_backup | - | Yes |
Operating System | netapp | solidfire_baseboard_management_controller_firmware | - | Yes |