An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Jun 16, 2020 | Apr 14, 2020 |
| Debian | — | Upgrade xen | Jul 14, 2020 | Apr 14, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-tools. | Jun 15, 2020 | Apr 14, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 14, 2020 |
| Suse | — | Upgrade xen-toolsUpgrade xen-tools-xendomains-wait-diskUpgrade xen-kmp-defaultUpgrade xen-kmp-paeUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xen-develUpgrade xen-tools-domUUpgrade xen-doc-htmlUpgrade xen | May 1, 2020 | Apr 14, 2020 |
| Ubuntu | — | Upgrade xen-utils-commonUpgrade libxenevtchn1Upgrade xen-hypervisor-4.11-amd64Upgrade xenstore-utilsUpgrade xen-hypervisor-4.11-arm64Upgrade xen-hypervisor-4.11-armhfUpgrade libxenmisc4.11Upgrade xen-utils-4.11Upgrade libxendevicemodel1Upgrade libxengnttab1 | Sep 20, 2022 | Apr 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub