Integer overflow in Xen - CVE-2018-10982

 

Integer overflow in Xen - CVE-2018-10982

Published: May 15, 2018 / Updated: May 15, 2018


Vulnerability identifier: #VU12648
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10982
CWE-ID: CWE-190
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to cause DoS condition or gain elevated privileges on the target system.

The weakness exists due to an array overrun condition that occurs when the High Precision Event Timer (HPET) timer is configured to deliver interrupts in IO-APIC mode. An adjacent attacker who has the HPET timer configured to deliver interrupts in IO-APIC mode can cause the service to crash or gain root privileges. 

Affected software

Xen
Debian Linux
Gentoo Linux
Fedora
xen (Alpine package)
openSUSE Leap
xen

How to mitigate CVE-2018-10982

Install update from vendor's website.

xen (Alpine package) - update to 4.6.6-r5
xen - addressed in versions 4.8.3-5.fc26, 4.9.2-3.fc27, 4.10.1-2.fc28

External References

Related Security Bulletins