Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr4c-368c-2fc2

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.

EPSS

Процентиль: 23%
0.00303
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 6.3
ubuntu
почти 10 лет назад

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.

CVSS3: 6.1
redhat
почти 10 лет назад

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.

CVSS3: 6.3
nvd
почти 10 лет назад

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.

CVSS3: 6.3
debian
почти 10 лет назад

Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which ...

suse-cvrf
больше 9 лет назад

Security update for xen

EPSS

Процентиль: 23%
0.00303
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-362