PT-2019-4846 · Xen+1 · Xen+1

Published

2019-12-11

·

Updated

2020-01-13

·

CVE-2019-19582

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.13
Description An issue in Xen allows x86 guest OS users to cause a denial of service (infinite loop) due to mishandled bit iteration. The hypervisor uses bitmaps to track state, and iteration over all bits may misbehave in certain corner cases, potentially resulting in infinite loops and a hypervisor crash or hang. This can lead to a Denial of Service (DoS). The issue is related to the handling of bitmaps with a compile-time known size of 64, which may incur undefined behavior on x86 accesses.
Recommendations For Xen versions prior to 4.13, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restricting access to certain hypervisor functions that handle bit iteration may help minimize the risk of a denial of service. However, the exact functions or parameters to restrict are not specified, so caution is advised when attempting any mitigation measures.

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01430
CVE-2019-19582
DSA-4602-1
OPENSUSE-SU-2020:0011-1
SUSE-SU-2019:3296-1
SUSE-SU-2019:3297-1
SUSE-SU-2019:3309-1
SUSE-SU-2019:3310-1
SUSE-SU-2019:3338-1

Affected Products

Suse
Xen