Integer overflow in Xen - CVE-2018-10982
Published: May 15, 2018 / Updated: May 15, 2018
Vulnerability identifier: #VU12648
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10982
CWE-ID: CWE-190
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an adjacent attacker to cause DoS condition or gain elevated privileges on the target system.
The weakness exists due to an array overrun condition that occurs when the High Precision Event Timer (HPET) timer is configured to deliver interrupts in IO-APIC mode. An adjacent attacker who has the HPET timer configured to deliver interrupts in IO-APIC mode can cause the service to crash or gain root privileges.
The weakness exists due to an array overrun condition that occurs when the High Precision Event Timer (HPET) timer is configured to deliver interrupts in IO-APIC mode. An adjacent attacker who has the HPET timer configured to deliver interrupts in IO-APIC mode can cause the service to crash or gain root privileges.
Affected software
Xen
Debian Linux
Gentoo Linux
Fedora
xen (Alpine package)
openSUSE Leap
xen
Debian Linux
Gentoo Linux
Fedora
xen (Alpine package)
openSUSE Leap
xen
How to mitigate CVE-2018-10982
Install update from vendor's website.
xen (Alpine package) - update to 4.6.6-r5
xen - addressed in versions 4.8.3-5.fc26, 4.9.2-3.fc27, 4.10.1-2.fc28
xen - addressed in versions 4.8.3-5.fc26, 4.9.2-3.fc27, 4.10.1-2.fc28