Denial of service in Xen - CVE-2018-15469
Published: August 20, 2018 / Updated: August 21, 2018
Vulnerability details
The vulnerability allows an adjacent attacker to cause DoS condition on the target system.
The vulnerability exists due to improper implementation of version 2 of grant tables in the affected software, in the hypervisor or in Linux. An adjacent attacker can request version 2 grant tables, trigger a BUG() check and cause the service to crash.
Affected software
Gentoo Linux
Opensuse
Fedora
xen (Alpine package)
xen
How to mitigate CVE-2018-15469
xen - addressed in versions 4.9.2-7.fc27, 4.10.1-6.fc28