PT-2018-3388 · Xen+4 · Xen+4

Felix Wilhelm

·

Published

2018-08-16

·

Updated

2023-10-03

·

CVE-2018-15471

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Xen versions prior to 4.11.x Linux kernel versions prior to 4.18.1
Description: The issue is related to the xenvif set hash mapping function in the Xen hypervisor, which is connected to an integer overflow when handling requests to the netback driver. This can allow an attacker to gain unauthorized access to information and disrupt its integrity and availability. The Linux netback driver allows frontends to control the mapping of requests to request queues. When processing a request to set or change this mapping, some input validation was missing or flawed, leading to out-of-bounds access in hash handling. A malicious or buggy frontend may cause the backend to make out-of-bounds memory accesses, potentially resulting in privilege escalation, Denial of Service (DoS), or information leaks.
Recommendations: For Xen versions prior to 4.11.x, update to a version that includes the fix for the xenvif set hash mapping function. For Linux kernel versions prior to 4.18.1, update to a version that includes the fix for the netback driver. As a temporary workaround, consider restricting access to the netback driver to minimize the risk of exploitation.

Fix

DoS

Integer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2203
ALT-PU-2018-2210
ALT-PU-2018-2490
ALT-PU-2018-2502
ALT-PU-2019-1433
BDU:2020-00735
CVE-2018-15471
DLA-1715-1
DSA-4313-1
MGASA-2018-0417
MGASA-2018-0418
MGASA-2018-0419
SUSE-SU-2018:2677-1
SUSE-SU-2018:2678-1
SUSE-SU-2018:2933-1
SUSE-SU-2018:2935-1
SUSE-SU-2018_2677-1
USN-3819-1
USN-3820-1
USN-3820-2
USN-3820-3

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu
Xen