Lucene search

K
redhatcveRedhat.comRH:CVE-2020-11741
HistoryApr 14, 2020 - 7:31 p.m.

CVE-2020-11741

2020-04-1419:31:13
redhat.com
access.redhat.com
15

0.0004 Low

EPSS

Percentile

14.2%

A flaw was found in Xenoprof in the Xen virtual machine through version 4.13.x, where it allows guest OS users, with active profiling, to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests with β€œactive” profiling enabled by the administrator, the Xenoprof code uses the standard Xen shared ring structure. With this flaw, the code does not treat the guest as a potential attacker, and it trusts the guest not to modify the buffer size information and not modify the head/tail pointers in unexpected ways, which can lead to a denial of service or escalation of privileges.