construction involves building the tables in local memory, which are
then copied into guest memory. While actually used parts of the local
memory are filled in correctly, excess space that is being allocated is
left with its prior contents.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5836-1 | xen security update |
Solution
No solution given by the vendor.
Workaround
Running only PV or HVM guests will avoid this vulnerability.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 31 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-276 | |
| Metrics |
cvssV3_1
|
Thu, 19 Dec 2024 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 19 Dec 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents. | |
| Title | libxl leaks data to PVH guests via ACPI tables | |
| References |
|
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2024-12-31T18:57:41.513Z
Reserved: 2024-09-09T14:43:11.826Z
Link: CVE-2024-45819
Updated: 2024-12-19T12:04:50.065Z
Status : Awaiting Analysis
Published: 2024-12-19T12:15:16.673
Modified: 2024-12-31T19:15:46.797
Link: CVE-2024-45819
No data.
OpenCVE Enrichment
Updated: 2025-07-15T08:04:28Z
Debian DSA