PT-2024-10469 · Xen+3 · Xen+3

Jason Andryuk

·

Published

2024-11-12

·

Updated

2025-11-09

·

CVE-2024-45819

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue is related to the construction of ACPI tables for PVH guests by the toolstack, which involves building the tables in local memory before copying them into guest memory. The excess space allocated in local memory is left with its prior contents, potentially leading to a data leak. This could allow an attacker to access confidential information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2025-01009
CVE-2024-45819
DSA-5836-1
MGASA-2025-0270
OPENSUSE-SU-2024:14530-1
OPENSUSE-SU-2024_3977-1
OPENSUSE-SU-2024_3980-1
OPENSUSE-SU-2024_4116-1
OPENSUSE-SU-2024_4163-1
SUSE-SU-2024:3977-1
SUSE-SU-2024:3979-1
SUSE-SU-2024:3980-1
SUSE-SU-2024:4073-1
SUSE-SU-2024:4116-1
SUSE-SU-2024:4163-1

Affected Products

Debian
Red Os
Suse
Xen