PT-2019-5139 · Xen+1 · Xen+1
Jan Beulich
·
Published
2019-10-07
·
Updated
2022-03-31
·
CVE-2019-17340
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xen versions prior to 4.12
Description
The issue is related to the mishandling of grant-table transfer requests, allowing x86 guest OS users to cause a denial of service or gain privileges. It is also associated with an insufficient input validation mechanism, which can be exploited to gain unauthorized access to confidential data, cause a denial of service, and impact data integrity.
Recommendations
For Xen versions prior to 4.12, update to version 4.12 or later to resolve the issue.
At the moment, there is no information about other versions that contain a fix for this issue.
Fix
DoS
Memory Leak
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Xen