Resource management error in Xen - CVE-2019-17345
Published: March 5, 2019 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error related to page type reference counting with failed IOMMU update. A local user of guest operating system can use a specially crafted kernel to perform denial of service attack against the host system.
Affected software
Debian Linux
xen (Alpine package)
xen (Debian package)