PT-2019-4843 · Amd+1 · Xen+1

Andrew Cooper

+1

·

Published

2019-12-11

·

Updated

2020-08-24

·

CVE-2019-19577

CVSS v3.1

7.2

High

VectorAV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.13
Description An issue in Xen allows x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. The vulnerability is related to the dynamic adaptation of the number of levels of pagetables in the IOMMU according to the guest's address space size. A malicious guest administrator can cause Xen to access data structures while they are being modified, causing Xen to crash. Privilege escalation is thought to be very difficult but cannot be ruled out. Additionally, there is a potential memory leak of 4kb per guest boot, under memory pressure. The vulnerability can be exploited when guests are given direct access to physical devices, and only HVM guests can exploit the vulnerability.
Recommendations For Xen versions prior to 4.13, update to a version that includes the necessary patches to fix the issue. As a temporary workaround, consider disabling PCI pass-through to minimize the risk of exploitation. Restrict access to physical devices for HVM guests until the issue is resolved.

Fix

DoS

Memory Leak

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01427
CVE-2019-19577
DSA-4602-1
OPENSUSE-SU-2020:0011-1
SUSE-SU-2019:3296-1
SUSE-SU-2019:3297-1
SUSE-SU-2019:3309-1
SUSE-SU-2019:3310-1
SUSE-SU-2019:3338-1
SUSE-SU-2019_3296-1
SUSE-SU-2019_3338-1
SUSE-SU-2020:0334-1
SUSE-SU-2020:0388-1
SUSE-SU-2020:14444-1
SUSE-SU-2020:1630-1
SUSE-SU-2020_1630-1

Affected Products

Suse
Xen