Loading HuntDB...

GHSA-pwx9-2gvj-242v

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the hypervisor routines used for shadow page handling it is possible for a guest with a PCI device passed through to cause the hypervisor to access an arbitrary pointer partially under guest control.

Related CVEs

Key Information

GHSA ID
GHSA-pwx9-2gvj-242v
Published
April 25, 2023 3:30 PM
Last Modified
February 4, 2024 9:30 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.