Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18259
HistoryMay 02, 2019 - 6:36 a.m.

Information Disclosure

2019-05-0206:36:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.001 Low

EPSS

Percentile

25.3%

QEMU is vulnerable to information disclosure attacks. This is because the patch_instruction function in hw/i386/kvmvapic.c does not initialize the imm32 variable which allows a local attacker to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).

References