Skip to content

kernel CVE-2021-28711

Moderate
cbgbt published GHSA-3rf6-cp76-q6v5 Jan 26, 2022

Package

kernel (bottlerocket)

Affected versions

< 1.5.3

Patched versions

1.5.3

Description

A denial of service flaw for virtual machine guests in the Linux kernel's Xen hypervisor subsystem was found in the way users call some interrupts with high frequency from one of the guests. A local user could use this flaw to starve the resources resulting in a denial of service.

Severity

Moderate

CVE ID

CVE-2021-28711

Weaknesses

No CWEs