Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
QEMU 信息泄露漏洞
Vulnerability Description
QEMU(Quick Emulator)是法国法布里斯-贝拉(Fabrice Bellard)个人开发者的一套模拟处理器软件。该软件具有速度快、跨平台等特点。 QEMU存在信息泄露漏洞,该漏洞源于程序没有初始化imm32变量。本地攻击者可通过该漏洞获取主机栈内存中的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A