PT-2023-24814 · Xen+2 · Xen+2
Jan Beulich
+1
·
Publicado
2023-09-20
·
Atualizado
2024-06-15
·
CVE-2023-34322
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xen (affected versions not specified)
Description
The issue arises when PV guests are run in shadow paging mode to work around kernels unaware of L1TF. In this mode, Xen and shadowed PV guests run directly on the respective shadow page tables. For 64-bit PV guests, this means running on the shadow of the guest root page table. When dealing with a shortage of memory in the shadow pool associated with a domain, shadows of page tables may be torn down, including the shadow root page table that the CPU is presently running on. A precaution exists to prevent the tearing down of the underlying live page table, but the time window covered by this precaution is not large enough.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Suse
Xen