Impact
This vulnerability allows a Xen guest to perform an out‑of‑bounds read of the host’s CMOS memory emulation array because the hypervisor fails to lock the index before concurrent modification. The read can expose data that should be confined to a guest session, potentially leaking sensitive configuration or state information. The weakness affects confidentiality by allowing a malicious guest to see data it should not access, but it does not grant execution or denial of service capabilities.
Affected Systems
The flaw exists in Xen hypervisor when running on x86 architecture. No specific version range is listed in the advisory, so any Xen release that implements the vRTC emulation routine without proper synchronization is likely affected. Xen deployments with guests that rely on emulated CMOS I/O operations fall under the risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact for information disclosure. The EPSS score of less than 1% suggests that, at the time of analysis, the likelihood of exploitation is very low. Xen’s KEV status is not listed, so no active known exploits are circulating. The attack vector is likely intra‑host; a malicious or compromised guest can modify the CMOS index after the check, triggering the out‑of‑bounds read. Effective exploitation requires the ability to run code inside a guest and to coordinate timing with the hypervisor’s I/O handling, conditions that are normally controlled by the host administrator. While the risk is moderate to high, the practical chance of exploitation remains low without a convincing threat scenario.
OpenCVE Enrichment
Debian DSA