Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3635-87f7-gfgj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

EPSS

Процентиль: 32%
0.00123
Низкий

8.8 High

CVSS3

Дефекты

CWE-436

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

CVSS3: 5.1
redhat
около 7 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

CVSS3: 8.8
nvd
около 7 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

CVSS3: 8.8
debian
около 7 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS ...

CVSS3: 8.8
fstec
около 7 лет назад

Уязвимость интерпретации структуры данных union гипервизора Xen, связанная с теневой подкачкой данных, позволяющая нарушителю вызвать отказ в обслуживании или повысить свои привилегии в системе

EPSS

Процентиль: 32%
0.00123
Низкий

8.8 High

CVSS3

Дефекты

CWE-436