Information disclosure in Xen - CVE-2018-10472
Published: April 28, 2018 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows an adjacent attacker to obtain potentially sensitive information.
The weakness exists due to improper information control. An adjacent attacker can supply a specially crafted CDROM image to read arbitrary files or device nodes on the dom0 filesystem with the privileges of the quem devicemodel process.
Affected software
Fedora
xen