Total vulnerabilities in the database
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
Software | From | Fixed in |
---|---|---|
xen / xen | - | 4.14.0.x |
fedoraproject / fedora | 32 | 32.x |
debian / debian_linux | 10.0 | 10.0.x |