PT-2018-3390 · Xen+1 · Xen+1

Julien Grall

·

Publicado

2018-12-07

·

Atualizado

2024-06-15

·

CVE-2018-19963

CVSS v3.1

7.8

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Xen version 4.11
Description: The issue is related to mishandled x86 IOREQ server resource accounting for external emulators, which can be exploited by HVM guest OS users. This exploitation may cause a denial of service, resulting in a host OS crash, or possibly allow attackers to gain host OS privileges.
Recommendations: For Xen version 4.11, consider restricting access to external emulators to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the external emulator functionality may help prevent the issue from being exploited.

Correção

DoS

Assertion Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00737
CVE-2018-19963
OPENSUSE-SU-2024:11520-1
SUSE-SU-2019:0003-1

Produtos afetados

Suse
Xen