PT-2018-13039 · Xen+1 · Xen+1

Christian Lindig

·

Published

2018-08-16

·

Updated

2024-06-15

·

CVE-2018-15470

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.12
Description An issue in the logic of oxenstored for handling writes allows a malicious or buggy guest to write an unbounded number of xenstore entries, causing unbounded memory usage in oxenstored. This can lead to a system-wide denial of service.
Recommendations For Xen versions prior to 4.12, update to version 4.12 or later to resolve the issue.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15470
DLA-1577-1
DSA-4274-1
OPENSUSE-SU-2018_4304-1
OPENSUSE-SU-2024:11520-1
SUSE-SU-2018:3490-1
SUSE-SU-2018:4300-1

Affected Products

Suse
Xen