PT-2018-3390 · Xen+1 · Xen+1

Julien Grall

·

Published

2018-12-07

·

Updated

2024-06-15

·

CVE-2018-19963

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Xen version 4.11
Description: The issue is related to mishandled x86 IOREQ server resource accounting for external emulators, which can be exploited by HVM guest OS users. This exploitation may cause a denial of service, resulting in a host OS crash, or possibly allow attackers to gain host OS privileges.
Recommendations: For Xen version 4.11, consider restricting access to external emulators to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the external emulator functionality may help prevent the issue from being exploited.

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00737
CVE-2018-19963
OPENSUSE-SU-2024:11520-1
SUSE-SU-2019:0003-1

Affected Products

Suse
Xen