Resource management error in Xen - CVE-2019-17348
Published: March 5, 2019 / Updated: July 28, 2020
Vulnerability identifier: #VU17899
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H]
CVE-ID: CVE-2019-17348
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient TLB flushing when using PCID on 64-bit x86 PV guest systems. A local user with access to guest operating system can use a specially crafted program to crash the Xen host.
Affected software
Xen
Debian Linux
xen (Alpine package)
xen (Debian package)
Debian Linux
xen (Alpine package)
xen (Debian package)
How to mitigate CVE-2019-17348
Apply the following patches:
xen (Debian package) - addressed in versions 4.8.5.final+shim4.10.4-1+deb9u12, 4.11.3+24-g14b62ab3e5-1~deb10u1