PT-2023-24814 · Xen+2 · Xen+2

Jan Beulich

+1

·

Publicado

2023-09-20

·

Atualizado

2024-06-15

·

CVE-2023-34322

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue arises when PV guests are run in shadow paging mode to work around kernels unaware of L1TF. In this mode, Xen and shadowed PV guests run directly on the respective shadow page tables. For 64-bit PV guests, this means running on the shadow of the guest root page table. When dealing with a shortage of memory in the shadow pool associated with a domain, shadows of page tables may be torn down, including the shadow root page table that the CPU is presently running on. A precaution exists to prevent the tearing down of the underlying live page table, but the time window covered by this precaution is not large enough.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-34322
OPENSUSE-SU-2023_3831-1
OPENSUSE-SU-2023_3832-1
OPENSUSE-SU-2023_4475-1
OPENSUSE-SU-2023_4476-1
OPENSUSE-SU-2024:13257-1
SUSE-SU-2023:3831-1
SUSE-SU-2023:3832-1
SUSE-SU-2023:3894-1
SUSE-SU-2023:3895-1
SUSE-SU-2023:3902-1
SUSE-SU-2023:3903-1
SUSE-SU-2023:4475-1
SUSE-SU-2023:4476-1

Produtos afetados

Debian
Suse
Xen