CVE-2024-45819Incorrect Default Permissions in XEN

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 77.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19

Description

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Alpinexen/xen< 4.16.6-r3+6
Debianxen/xen< 4.17.5+23-ga4e5191dc0-1+2
NVDxen/xen

Patches

🔴Vulnerability Details

4
GHSA
GHSA-4rgq-6973-6xxh: PVH guests have their ACPI tables constructed by the toolstack2024-12-19
CVEList
libxl leaks data to PVH guests via ACPI tables2024-12-19
OSV
CVE-2024-45819: PVH guests have their ACPI tables constructed by the toolstack2024-12-19
OSV
CVE-2024-45819: PVH guests have their ACPI tables constructed by the toolstack2024-12-19

📋Vendor Advisories

1
Debian
CVE-2024-45819: xen - PVH guests have their ACPI tables constructed by the toolstack. The constructio...2024