Описание
The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive information via the GNTTABOP_setup_table subhypercall.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 4.4.0-0ubuntu6 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [4.4.0-0ubuntu5.1]] |
| lucid | DNE | |
| precise | not-affected | |
| saucy | not-affected | |
| trusty | released | 4.4.0-0ubuntu5.1 |
| trusty/esm | DNE | trusty was released [4.4.0-0ubuntu5.1] |
| upstream | needed |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| lucid | not-affected | |
| precise | DNE | |
| saucy | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | ignored | end of life |
Показывать по
EPSS
2.7 Low
CVSS2
Связанные уязвимости
The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive information via the GNTTABOP_setup_table subhypercall.
The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, wh ...
The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive information via the GNTTABOP_setup_table subhypercall.
EPSS
2.7 Low
CVSS2