CVE-2021-28038

MEDIUM

Description

An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issue exists because of an incomplete fix for CVE-2021-26931.

References

http://www.openwall.com/lists/oss-security/2021/03/05/1

http://xenbits.xen.org/xsa/advisory-367.html

https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html

https://lists.debian.org/debian-lts-announce/2021/03/msg00035.html

https://security.netapp.com/advisory/ntap-20210409-0001/

Details

Source: MITRE

Published: 2021-03-05

Updated: 2021-04-09

Type: CWE-770

Risk Information

CVSS v2.0

Base Score: 4.9

Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Impact Score: 6.9

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3.0

Base Score: 6.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Impact Score: 4

Exploitability Score: 2

Severity: MEDIUM

Tenable Plugins

View all (13 total)

IDNameProductFamilySeverity
148700SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1210-1)NessusSuSE Local Security Checks
high
148698SUSE SLES15 Security Update : kernel (SUSE-SU-2021:1211-1)NessusSuSE Local Security Checks
high
148674Citrix Hypervisor <= 8.2 LTSR DoS (CTX306565)NessusMisc.
high
148509SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1175-1)NessusSuSE Local Security Checks
high
148498Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-4904-1)NessusUbuntu Local Security Checks
high
148496Ubuntu 20.04 LTS : Linux kernel (OEM) vulnerabilities (USN-4911-1)NessusUbuntu Local Security Checks
high
148453Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2021-9172)NessusOracle Linux Local Security Checks
medium
148452Oracle Linux 7 : Unbreakable Enterprise kernel-container (ELSA-2021-9175)NessusOracle Linux Local Security Checks
medium
148438openSUSE Security Update : the Linux Kernel (openSUSE-2021-532)NessusSuSE Local Security Checks
high
148254Debian DLA-2610-1 : linux-4.19 security updateNessusDebian Local Security Checks
high
147919Amazon Linux AMI : kernel (ALAS-2021-1487)NessusAmazon Linux Local Security Checks
medium
147914Amazon Linux 2 : kernel (ALAS-2021-1616)NessusAmazon Linux Local Security Checks
medium
147532Debian DLA-2586-1 : linux security updateNessusDebian Local Security Checks
high