Total vulnerabilities in the database
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
Software | From | Fixed in |
---|---|---|
qemu / qemu | - | 2.6.2.x |
canonical / ubuntu_linux | 16.04 | 16.04.x |
canonical / ubuntu_linux | 15.10 | 15.10.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
debian / debian_linux | 8.0 | 8.0.x |
redhat / enterprise_linux_desktop | 7.0 | 7.0.x |
redhat / enterprise_linux_workstation | 7.0 | 7.0.x |
redhat / enterprise_linux_server | 7.0 | 7.0.x |
redhat / openstack | 7.0 | 7.0.x |
redhat / openstack | 6.0 | 6.0.x |
redhat / enterprise_linux_server_aus | 7.4 | 7.4.x |
redhat / enterprise_linux_eus | 7.4 | 7.4.x |
redhat / enterprise_linux_eus | 7.5 | 7.5.x |
redhat / openstack | 10 | 10.x |
redhat / enterprise_linux_server_tus | 7.6 | 7.6.x |
redhat / enterprise_linux_server_aus | 7.6 | 7.6.x |
redhat / enterprise_linux_eus | 7.6 | 7.6.x |
redhat / openstack | 9 | 9.x |
redhat / openstack | 8 | 8.x |
redhat / enterprise_linux_server_aus | 7.7 | 7.7.x |
redhat / enterprise_linux_server_tus | 7.7 | 7.7.x |
redhat / enterprise_linux_eus | 7.7 | 7.7.x |
redhat / openstack | 11 | 11.x |
redhat / virtualization | 4.0 | 4.0.x |