PT-2018-3390 · Xen+1 · Xen+1
Julien Grall
·
Published
2018-12-07
·
Updated
2024-06-15
·
CVE-2018-19963
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Xen version 4.11
Description:
The issue is related to mishandled x86 IOREQ server resource accounting for external emulators, which can be exploited by HVM guest OS users. This exploitation may cause a denial of service, resulting in a host OS crash, or possibly allow attackers to gain host OS privileges.
Recommendations:
For Xen version 4.11, consider restricting access to external emulators to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the external emulator functionality may help prevent the issue from being exploited.
Fix
DoS
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen