← back
CVE-2021-28700

CVE-2021-28700

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
In short

In Xen's dom0less feature, unprivileged domains can allocate unlimited memory, bypassing the administrator's configured limits. This allows a single domain to consume all available memory and crash the entire system.

Technical detail

The dom0less feature in Xen/ARM fails to enforce memory limits on unprivileged domains created directly by the hypervisor. An authenticated domain administrator can trigger unbounded memory allocation, leading to resource exhaustion and denial of service across the virtualized environment. Mitigation requires explicit memory limit configuration at domain creation time.

Summary generated and translated by AI from the official description.
xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured.
Affected products
Xen · xen