https://seclists.org/oss-sec/2024/q4/89: Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables
Published Nov 12, 2024
·Updated
Affected Software
1 affected component
Xen Project Xen
Frequently Asked Questions
1
What is the severity of CVE-2024-45819?
CVE-2024-45819 is considered a high-severity vulnerability as it allows data leakage to PVH guests.
2
How do I fix CVE-2024-45819?
To address CVE-2024-45819, update to the latest version of the Xen Project Xen software that has patched this vulnerability.
3
Who is affected by CVE-2024-45819?
Only PVH guests are affected by CVE-2024-45819; HVM and PV guests are not impacted.
4
What types of guests can exploit CVE-2024-45819?
CVE-2024-45819 can only be exploited by PVH guests running on unpatched versions of Xen.
5
Are there any mitigations for CVE-2024-45819?
Currently, the best mitigation for CVE-2024-45819 is to apply the security updates provided by the Xen Project.