Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf86-2wqg-v74w

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

EPSS

Процентиль: 84%
0.02549
Низкий

10 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 10
ubuntu
около 9 лет назад

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

CVSS3: 8.5
redhat
около 9 лет назад

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

CVSS3: 10
nvd
около 9 лет назад

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

CVSS3: 10
debian
около 9 лет назад

The grant-table feature in Xen through 4.8.x does not ensure sufficien ...

fstec
около 9 лет назад

Уязвимость компонента grant-table гипервизора Xen, позволяющая нарушителю вызвать отказ в обслуживании или получить привилегированный доступ к хосту

EPSS

Процентиль: 84%
0.02549
Низкий

10 Critical

CVSS3

Дефекты

CWE-119