An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
2020-10-22T21:15:13.950
2024-11-21T05:21:38.207
Modified
CVSSv3.1: 7.0 (HIGH)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | xen | xen | ≤ 4.14.0 | Yes |
Operating System | fedoraproject | fedora | 31 | Yes |
Operating System | opensuse | leap | 15.1 | Yes |
Operating System | opensuse | leap | 15.2 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |