PT-2019-4845 · Xen+1 · Xen+1

Sarah Newman

·

Published

2019-04-13

·

Updated

2020-08-04

·

CVE-2019-19580

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.13
Description The issue allows x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. A malicious PV guest administrator may be able to escalate their privilege to that of the host. The vulnerability is related to incomplete fix for a previous issue and affects all security-supported versions of Xen. Only x86 systems are affected, and only x86 PV guests can leverage the vulnerability. The exploitation of this issue may require very precise timing, which could be difficult to achieve in practice.
Recommendations For Xen versions prior to 4.13, update to a version that includes the complete fix for the issue, as the current version is vulnerable to privilege escalation attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01429
CVE-2019-19580
DSA-4602-1
OPENSUSE-SU-2020:0011-1
SUSE-SU-2019:3296-1
SUSE-SU-2019:3297-1
SUSE-SU-2019:3309-1
SUSE-SU-2019:3310-1
SUSE-SU-2019:3338-1
SUSE-SU-2020:0334-1
SUSE-SU-2020:0388-1
SUSE-SU-2020:14444-1
SUSE-SU-2020:1630-1
SUSE-SU-2020_1630-1

Affected Products

Suse
Xen