CVE-2024-45819

MEDIUM

Xen - Incorrect Default Permissions

Title source: rule

Description

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents.

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 19.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-276
Status published

Affected Products (1)

xen/xen

Timeline

Published Dec 19, 2024
Tracked Since Feb 18, 2026