Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialized, that the latter are also ready for use.
Created xen tracking bugs for this issue: Affects: fedora-all [bug 1907931]
External References: https://www.openwall.com/lists/oss-security/2020/12/15/14
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.