The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
AND |
|
History
21 Nov 2024, 02:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=691a02e2ce0c413236a78dee6f2651c937b09fb0 - | |
References | () http://www.securityfocus.com/bid/86067 - Third Party Advisory, VDB Entry | |
References | () http://www.ubuntu.com/usn/USN-2974-1 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2017:1856 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2017:2392 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2017:2408 - Third Party Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1313686 - Issue Tracking, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2018/11/msg00038.html - Mailing List, Third Party Advisory | |
References | () https://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01106.html - Patch, Third Party Advisory | |
References | () https://lists.gnu.org/archive/html/qemu-devel/2016-04/msg01118.html - Patch, Third Party Advisory | |
References | () https://security.gentoo.org/glsa/201609-01 - Third Party Advisory |
Information
Published : 2016-05-25 15:59
Updated : 2024-11-21 02:51
NVD link : CVE-2016-4020
Mitre link : CVE-2016-4020
CVE.ORG link : CVE-2016-4020
JSON object : View
Products Affected
redhat
- enterprise_linux_server
- openstack
- virtualization
- enterprise_linux_desktop
- enterprise_linux
- enterprise_linux_server_aus
- enterprise_linux_eus
- enterprise_linux_server_tus
- enterprise_linux_workstation
canonical
- ubuntu_linux
qemu
- qemu
debian
- debian_linux
CWE