{"id":"CVE-2021-28706","details":"guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.","modified":"2026-03-13T01:59:42.686185Z","published":"2021-11-24T01:15:08.127Z","related":["SUSE-SU-2021:14848-1","SUSE-SU-2021:3813-1","SUSE-SU-2021:3842-1","SUSE-SU-2021:3849-1","SUSE-SU-2021:3851-1","SUSE-SU-2021:3852-1","SUSE-SU-2021:3888-1","SUSE-SU-2021:3968-1","SUSE-SU-2021:3977-1","openSUSE-SU-2021:1543-1","openSUSE-SU-2021:3968-1"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7ZGWVVRI4XY2XSTBI3XEMWBXPDVX6OT/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PXUI4VMD52CH3T7YXAG3J2JW7ZNN3SXF/"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202402-07"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-5017"},{"type":"FIX","url":"https://xenbits.xenproject.org/xsa/advisory-385.txt"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"3.2"},{"fixed":"4.12"}]},{"events":[{"introduced":"0"},{"last_affected":"34"}]},{"events":[{"introduced":"0"},{"last_affected":"35"}]},{"events":[{"introduced":"0"},{"last_affected":"11.0"}]}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-28706.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"}]}