Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local users to cause a denial of service (host crash) or obtain sensitive information from hypervisor memory by leveraging a FLASK_AVC_CACHESTAT hypercall, which triggers a buffer over-read.
CVSS Details
- CVSS 3.1 Base Score: 7.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xen | Jul 30, 2024 | Apr 1, 2014 |
| Gentoo Linux | — | Upgrade app-emulations/xen-tools.Upgrade app-emulations/xen-pvgrub.Upgrade app-emulations/xen. | Oct 30, 2017 | Apr 1, 2014 |
| Suse | — | Upgrade xen-doc-htmlUpgrade xen-libsUpgrade xen-tools-domUUpgrade xen-kmp-defaultUpgrade xen-develUpgrade xen-libs-32bitUpgrade xen-doc-pdfUpgrade xen-kmp-paeUpgrade xen-toolsUpgrade xen | Dec 18, 2015 | Mar 14, 2014 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Apr 1, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub