脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
domctl lock open to abuse
脆弱性説明
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these operations may not be executed in parallel, so a system-wide lock is used. The way that lock is acquired is, however, not providing any fairness. This is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. This is CVE-2026-42490.
CVSS情報
N/A
脆弱性タイプ
N/A
脆弱性タイトル
Xen 竞争条件问题漏洞
脆弱性説明
Xen是Xen组织开源的一款开源的虚拟机监视器产品。该产品能够使不同和不兼容的操作系统运行在同一台计算机上,并支持在运行时进行迁移,保证正常运行并且避免宕机。 Xen存在竞争条件问题漏洞,该漏洞源于系统范围锁的获取方式未提供公平性,且当XSM/Flask启用时,某些操作中锁获取会先于权限检查,可能导致权限低的攻击者通过网络访问造成拒绝服务。
CVSS情報
N/A
脆弱性タイプ
N/A