The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3006-1 | xen security update |
EUVD |
EUVD-2013-4245 | The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:38:01.876Z
Reserved: 2013-06-12T00:00:00
Link: CVE-2013-4361
No data.
Status : Deferred
Published: 2013-10-01T17:55:03.570
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-4361
OpenCVE Enrichment
No data.
Debian DSA
EUVD