OSV 1.4.0 · unreviewed · 修改于 2023-01-20 02:30
发布时间
2022-02-19 08:01
GitHub 审查时间
—
NVD 发布时间
2022-02-19 02:15
源文件
advisories/unreviewed/2022/02/GHSA-2vg6-vx3w-m2r4/GHSA-2vg6-vx3w-m2r4.json
A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for example, outs or ins) using the exit reason SVM_EXIT_IOIO. This issue results in a crash of the entire system or a potential guest-to-host escape scenario.
该公告没有提供结构化的受影响软件包信息。