Lucene search

K
mageiaGentoo FoundationMGASA-2024-0115
HistoryApr 10, 2024 - 7:03 a.m.

Updated xen packages fix security vulnerabilities

2024-04-1007:03:52
Gentoo Foundation
advisories.mageia.org
14
xen
security vulnerabilities
x86
shadow stack
exceptions
emulation stubs
register file data sampling
ghostrace
speculative race conditions
cve-2023-46841
cve-2023-28746
cve-2024-2193
unix

6.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

x86: shadow stack vs exceptions from emulation stubs. (CVE-2023-46841) x86: Register File Data Sampling. (CVE-2023-28746) GhostRace: Speculative Race Conditions. (CVE-2024-2193)

OSVersionArchitecturePackageVersionFilename
Mageia9noarchxen<ย 4.17.3-1.1xen-4.17.3-1.1.mga9

6.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

7.3 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%