An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4723-1 | xen security update |
EUVD |
EUVD-2020-4082 | An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed. |
Ubuntu USN |
USN-5617-1 | Xen vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:41:59.488Z
Reserved: 2020-04-14T00:00:00
Link: CVE-2020-11740
No data.
Status : Modified
Published: 2020-04-14T13:15:12.767
Modified: 2024-11-21T04:58:31.487
Link: CVE-2020-11740
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN