Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xen PV guest 安全漏洞
Vulnerability Description
Xen是一款开源的虚拟机监视器,Xen PV guest是一款基于Xen的虚拟机。 Xen 4.3之前版本的Xen PV虚拟机中存在安全漏洞。攻击者可利用该漏洞读取主机PCI设备的空间内存,造成信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A