PT-2019-4839 · Xen+1 · Xen+1

Andrew Cooper

·

Published

2019-10-31

·

Updated

2023-03-29

·

CVE-2019-18425

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen versions 3.2 through 4.12.x
Description The issue is related to an error in the x86 PV emulation of the Xen hypervisor, specifically a missing check for the descriptor table limit. This could allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The vulnerability can be exploited by 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. The emulation of certain PV guest operations does not respect the guest-specified limits for descriptor table accesses, allowing 32-bit PV guest user mode to elevate its privileges to that of the guest kernel.
Recommendations For Xen versions 3.2 through 4.12.x, consider restricting the use of 32-bit PV guest user mode to minimize the risk of exploitation until a patch is available. As a temporary workaround, ensure that the guest kernel installs an LDT to prevent guest user mode from installing and using descriptors of their choice. Restrict access to the emulation of PV guest operations to prevent unauthorized elevation of privileges.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01423
CVE-2019-18425
DSA-4602-1
MGASA-2020-0113
OPENSUSE-SU-2019:2506-1
OPENSUSE-SU-2019_2506-1
SUSE-SU-2019:2960-1
SUSE-SU-2019:2961-1
SUSE-SU-2019:2962-1
SUSE-SU-2019:3297-1
SUSE-SU-2020:0334-1
SUSE-SU-2020:0388-1
SUSE-SU-2020:14444-1
SUSE-SU-2020:14448-1

Affected Products

Suse
Xen