• 公告ID (KylinSec-SA-2024-1098)

摘要:

In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

安全等级: Low

公告ID: KylinSec-SA-2024-1098

发布日期: 2024年2月26日

关联CVE: CVE-2023-21264  

  • 详细介绍

1. 漏洞描述

   

In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-21264 KY3.4-4A kernel Unaffected
CVE-2023-21264 KY3.4-5A kernel Unaffected
CVE-2023-21264 KY3.5.1 kernel Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-1097 下一篇:KylinSec-SA-2024-1099