| 概要 | In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is The first causes a buffer overflow as sprintf in buildid_show will 00000000 f4 91 51 f4 dd 38 9e 9d 65 47 52 eb 10 71 db 50 |..Q..8..eGR..q.P| So use a memcpy instead of sprintf to have the correct value: 00000000 f4 91 51 f4 dd 00 9e 9d 65 47 52 eb 10 71 db 50 |..Q.....eGR..q.P| (the above have a hack to embed a zero inside and check it's This is XSA-485 / CVE-2026-31786 |
|---|---|
| 公表日 | 2026年4月30日20:16 |
| 登録日 | 2026年5月1日4:07 |
| 最終更新日 | 2026年5月1日2:11 |