Information disclosure in Xen - CVE-2018-10472
Published: May 9, 2018 / Updated: May 10, 2018
Vulnerability details
The vulnerability allows an adjacent attacker to obtain potentially sensitive information on the target system.
The weakness exists in certain configurations due to improper information control. An adjacent attacker can read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
Affected software
Debian Linux
Gentoo Linux
SUSE Linux
Fedora
xen (Alpine package)
xen
How to mitigate CVE-2018-10472
xen - addressed in versions 4.8.3-4.fc26, 4.9.2-2.fc27, 4.10.0-9.fc28
External References
Related Security Bulletins
- SUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- OpenSUSE Linux update for xen
- Debian update for xen
- Gentoo update for Xen
- Information disclosure in xen (Alpine package)
- Fedora 28 update for xen
- Fedora 27 update for xen
- Fedora 26 update for xen