Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2016-04-13 15:59
Updated : 2024-02-04 18:53
NVD link : CVE-2015-8555
Mitre link : CVE-2015-8555
CVE.ORG link : CVE-2015-8555
JSON object : View
Products Affected
xen
- xen
citrix
- xenserver
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor