PT-2018-2671 · Amd+1 · Xen+1

Paul Durrant

·

Published

2018-12-07

·

Updated

2019-10-08

·

CVE-2018-19962

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.12
Description An issue in Xen on AMD x86 platforms allows guest OS users to potentially gain host OS privileges due to the unsafe combination of small IOMMU mappings into larger ones. This could enable an attacker to elevate their privileges.
Recommendations For Xen versions prior to 4.12, update to a version that includes the fix for this issue to prevent potential privilege escalation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01306
CVE-2018-19962
DLA-1949-1
DSA-4369-1
OPENSUSE-SU-2018_4111-1
OPENSUSE-SU-2018_4304-1
OPENSUSE-SU-2019_1226-1
SUSE-SU-2018:4070-1
SUSE-SU-2018:4300-1
SUSE-SU-2019:0003-1
SUSE-SU-2019:0020-1
SUSE-SU-2019:0825-1
SUSE-SU-2019:0827-1
SUSE-SU-2019:13921-1
SUSE-SU-2019:14011-1

Affected Products

Suse
Xen