Описание
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| linux | fixed | 4.19.37-1 | package | |
| linux | ignored | jessie | package | |
| linux | ignored | wheezy | package | |
| linux-2.6 | removed | package | ||
| linux-2.6 | no-dsa | squeeze | package |
Примечания
CVE for the incomplete patches from XSA-120 and supplied in
XSA-120 v5+ addendum patch.
Cf. https://bugzilla.redhat.com/show_bug.cgi?id=1289128#c2
http://xenbits.xen.org/xsa/advisory-120.html
Patch is discussed in http://thread.gmane.org/gmane.comp.emulators.xen.devel/140440/focus=140441
and http://thread.gmane.org/gmane.linux.kernel/1924087/focus=1924088
https://git.kernel.org/linus/7681f31ec9cdacab4fd10570be924f2cef6669ba
EPSS
Связанные уязвимости
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.
Уязвимость гипервизора Xen, связанная с ошибкой при обработке чисел, позволяющая нарушителю получить несанкционированный доступ к информации
EPSS