PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents.
History

Tue, 31 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Dec 2024 12:45:00 +0000


Thu, 19 Dec 2024 12:15:00 +0000

Type Values Removed Values Added
Description PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents.
Title libxl leaks data to PVH guests via ACPI tables
References

cve-icon MITRE

Status: PUBLISHED

Assigner: XEN

Published: 2024-12-19T12:00:50.271Z

Updated: 2024-12-31T18:57:41.513Z

Reserved: 2024-09-09T14:43:11.826Z

Link: CVE-2024-45819

cve-icon Vulnrichment

Updated: 2024-12-19T12:04:50.065Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-19T12:15:16.673

Modified: 2024-12-31T19:15:46.797

Link: CVE-2024-45819

cve-icon Redhat

No data.