PT-2018-11455 · Xen+1 · Xen+1

Andrew Reimers

·

Published

2018-06-27

·

Updated

2024-06-15

·

CVE-2018-12892

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen versions 4.7 through 4.10.x
Description An issue in Xen allows malicious guest administrators or users to write to supposedly read-only disk images. This affects emulated SCSI disks, but not IDE disks or CDROM devices. The vulnerability is present in systems using qemu-xen as the device model version and libxl or libxl-based toolstacks, including xl and libvirt with the libxl driver. The issue is exploitable if the malicious guest administrator has control of the guest kernel or guest kernel command line, especially in environments that support PVHVM.
Recommendations For Xen versions 4.7 through 4.10.x, consider disabling the use of emulated SCSI disks or restricting access to them until a patch is available. As a temporary workaround, avoid using libxl or libxl-based toolstacks, and instead use alternative configurations that do not rely on qemu-xen as the device model version. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12892
DSA-4236-1
OPENSUSE-SU-2018_2116-1
OPENSUSE-SU-2018_2211-1
OPENSUSE-SU-2024:11520-1
SUSE-SU-2018:1981-1
SUSE-SU-2018:2059-1
SUSE-SU-2018:2081-1
SUSE-SU-2018:2081-2

Affected Products

Suse
Xen