Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f5vc-gmmj-gpp6

Опубликовано: 27 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.

insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.

EPSS

Процентиль: 12%
0.00042
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 3 года назад

insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.

CVSS3: 8.8
nvd
почти 3 года назад

insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.

CVSS3: 8.8
debian
почти 3 года назад

insufficient TLB flush for x86 PV guests in shadow mode For migration ...

CVSS3: 8.8
fstec
почти 3 года назад

Уязвимость компонента Shadow Mode кроссплатформенного гипервизора Xen ядра операционной системы Linux, связанная с недостаточной проверкой входных данных, позволяющая нарушителю повысить свои привилегии

suse-cvrf
почти 3 года назад

Security update for xen

EPSS

Процентиль: 12%
0.00042
Низкий

8.8 High

CVSS3