#VU65351 Information disclosure in Xen - CVE-2022-33741
Published: July 15, 2022 / Updated: July 28, 2022
Xen
Xen Project
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to granularity of the grant table doesn't allow sharing less than a 4K page, leading to unrelated data residing in the same 4K page as data shared with a backend being accessible by such backend. A local user can gain unauthorized access to sensitive information on the system.