CVE-2024-45819

NameCVE-2024-45819
DescriptionPVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5836-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xen (PTS)bullseye4.14.6-1vulnerable
bullseye (security)4.14.5+94-ge49571868d-1vulnerable
bookworm4.17.3+10-g091466ba55-1~deb12u1vulnerable
bookworm (security)4.17.5+23-ga4e5191dc0-1fixed
trixie4.17.3+36-g54dacb5c02-1vulnerable
sid4.19.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xensourceexperimental4.19.1-1~exp1
xensourcebullseye(unfixed)end-of-life
xensourcebookworm4.17.5+23-ga4e5191dc0-1DSA-5836-1
xensource(unstable)4.19.1-1

Notes

[bullseye] - xen <end-of-life> (EOLed in Bullseye)
https://xenbits.xen.org/xsa/advisory-464.html

Search for package or bug name: Reporting problems