CVE-2016-4020

MEDIUM6.5EPSS 0.08%
發布日:2016/5/25修改日:2026/4/28
也稱為:DEBIAN-CVE-2016-4020

描述

The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

參考連結(1)