Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x89c-76jf-xx4h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.

EPSS

Процентиль: 37%
0.00155
Низкий

8.6 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 4 лет назад

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.

CVSS3: 8.6
nvd
около 4 лет назад

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit precision, which may overflow. It would then only be the overflowed (and hence small) number which gets compared against the established upper bound.

CVSS3: 8.6
debian
около 4 лет назад

guests may exceed their designated memory limit When a guest is permit ...

suse-cvrf
около 4 лет назад

Security update for xen

suse-cvrf
около 4 лет назад

Security update for xen

EPSS

Процентиль: 37%
0.00155
Низкий

8.6 High

CVSS3

Дефекты

CWE-770