#VU46972 Use of uninitialized resource in Xen - CVE-2020-25595
Published: September 23, 2020
Xen
Xen Project
Description
The vulnerability allows a remote user to escalate privileges on the host operating system.
The vulnerability exists due to PCI passthrough code reading back untrusted values fromhardware registers in Xen. A remote user on a guest operating system can run a specially crafted program to obtain potentially sensitive information from memory and crash Xen or escalate privileges on the hypervisor.
The vulnerability affects x86 systems with PCI passthrough support.