目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2021-28705— Xen 输入验证错误漏洞

AI 预测 4.4 利用难度: 中等 EPSS 0.33% · P26
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2021-28705 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain P2M aspects of individual pages via hypercalls. These hypercalls may act on ranges of pages specified via page orders (resulting in a power-of-2 number of pages). In some cases the hypervisor carries out the requests by splitting them into smaller chunks. Error handling in certain PoD cases has been insufficient in that in particular partial success of some operations was not properly accounted for. There are two code paths affected - page removal (CVE-2021-28705) and insertion of new pages (CVE-2021-28709). (We provide one patch which combines the fix to both issues.)
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Xen 输入验证错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Xen是英国剑桥(Cambridge)大学的一款开源的虚拟机监视器产品。该产品能够使不同和不兼容的操作系统运行在同一台计算机上,并支持在运行时进行迁移,保证正常运行并且避免宕机。 Xen 输入验证错误漏洞中存在输入验证错误漏洞。该漏洞源于在 x86 T 上部分成功的 P2M 更新问题[他的 CNA 信息记录与多个 CVE 相关;文本解释了哪些方面/漏洞对应于哪些 CVE。] x86 HVM 和 PVH 来宾可以在按需填充 (PoD) 模式下启动,以便为它们提供一种方法,以便以后轻松分配更多内存。访客可以通
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
Xenxen 4.14.x -
Xenxen 4.12.x -
Xenxen 4.15.x -
Xenxen xen-unstable -
Xenxen 4.13.x -

二、漏洞 CVE-2021-28705 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-28705 的情报信息

登录查看更多情报信息。

CVE-2021-28705 厂商安全公告 (2)

CVE-2021-28705 邮件列表归档 (1)

同批安全公告 · Xen · 2021-11-24 · 共 6 条

CVE-2021-28704Xen 命令注入漏洞
CVE-2021-28706Xen 缓冲区错误漏洞
CVE-2021-28707Xen 命令注入漏洞
CVE-2021-28708Xen 命令注入漏洞
CVE-2021-28709Xen 输入验证错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-28705

暂无评论


发表评论