Severe I/O Misconfiguration Vulnerability in Linux Kernel's Xen Virtualization
CVE-2021-28039
6.5MEDIUM
What is CVE-2021-28039?
A significant vulnerability has been identified in the Linux kernel versions 5.9.x through 5.11.3, specifically in configurations using Xen virtualization. This issue allows an x86 paravirtual (PV) guest operating system user to potentially crash the Dom0 or driver domain by executing a large volume of I/O operations. The vulnerability arises from incorrect handling of guest physical addresses, particularly in scenarios where CONFIG_XEN_UNPOPULATED_ALLOC is enabled while CONFIG_XEN_BALLOON_MEMORY_HOTPLUG is not. This may lead to system instability affecting host and guest environments.