Lucene search

K
cvelistRedhatCVELIST:CVE-2016-4020
HistoryMay 25, 2016 - 3:00 p.m.

CVE-2016-4020

2016-05-2515:00:00
redhat
www.cve.org
1

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.3%

The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.3%