Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28872
HistoryDec 31, 2020 - 5:03 p.m.

Arbitrary Code Execution

2020-12-3117:03:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
arbitrary code execution
xen
access rights
domain
xenstore
vulnerability

EPSS

0

Percentile

14.2%

xen is vulnerable to arbitrary code execution. The vulnerability exists access rights of Xenstore nodes are per domid, and existing granted access rights are not removed when a domain is being destroyed, allowing a new domain created with the same domid to inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Xenstore entries of a guest below /local/domain/ are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected.