漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unconditionally do TLB flushing ahead of page scrubbing
Vulnerability Description
x86 PV guests can free memory pages while still keeping a stale TLB entry
pointing to them. A TLB flush is only issued by Xen (if needed) when the
page is re-used. Since it's possible for the page to be scrubbed ahead of
the TLB flush, there's a window where a PV guest can modify an already
scrubbed page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Xen 资源管理错误漏洞
Vulnerability Description
Xen是Xen组织开源的一款开源的虚拟机监视器产品。该产品能够使不同和不兼容的操作系统运行在同一台计算机上,并支持在运行时进行迁移,保证正常运行并且避免宕机。 Xen存在资源管理错误漏洞,该漏洞源于x86 PV客户机释放内存页后仍保留过时的TLB条目,导致仅在页面被重新使用时才执行TLB刷新,且页面可能在刷新前被擦除,存在允许PV客户机修改已擦除页面的窗口期。
CVSS Information
N/A
Vulnerability Type
N/A