An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed.
References
Link | Resource |
---|---|
https://xenbits.xen.org/xsa/advisory-313.html | Patch Vendor Advisory |
http://xenbits.xen.org/xsa/advisory-313.html | Patch Vendor Advisory |
http://www.openwall.com/lists/oss-security/2020/04/14/1 | Mailing List Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YMAW7D2MP6RE4BFI5BZWOBBWGY3VSOFN/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5M2XRNCHOGGTJQBZQJ7DCV6ZNAKN3LE2/ | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00006.html | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NVTP4OYHCTRU3ONFJOFJQVNDFB25KLLG/ | Mailing List Third Party Advisory |
https://security.gentoo.org/glsa/202005-08 | Third Party Advisory |
https://www.debian.org/security/2020/dsa-4723 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2020-04-14 06:15
Updated : 2022-05-03 07:06
NVD link : CVE-2020-11740
Mitre link : CVE-2020-11740
JSON object : View
CWE
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
Products Affected
debian
- debian_linux
xen
- xen
fedoraproject
- fedora
opensuse
- leap