PT-2019-4846 · Xen+1 · Xen+1

Publicado

2019-12-11

·

Atualizado

2020-01-13

·

CVE-2019-19582

CVSS v3.1

6.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.13
Description An issue in Xen allows x86 guest OS users to cause a denial of service (infinite loop) due to mishandled bit iteration. The hypervisor uses bitmaps to track state, and iteration over all bits may misbehave in certain corner cases, potentially resulting in infinite loops and a hypervisor crash or hang. This can lead to a Denial of Service (DoS). The issue is related to the handling of bitmaps with a compile-time known size of 64, which may incur undefined behavior on x86 accesses.
Recommendations For Xen versions prior to 4.13, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restricting access to certain hypervisor functions that handle bit iteration may help minimize the risk of a denial of service. However, the exact functions or parameters to restrict are not specified, so caution is advised when attempting any mitigation measures.

Correção

DoS

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-01430
CVE-2019-19582
DSA-4602-1
OPENSUSE-SU-2020:0011-1
SUSE-SU-2019:3296-1
SUSE-SU-2019:3297-1
SUSE-SU-2019:3309-1
SUSE-SU-2019:3310-1
SUSE-SU-2019:3338-1

Produtos afetados

Suse
Xen