Permissions, Privileges, and Access Controls in Xen - CVE-2019-18425
Published: November 6, 2019
Vulnerability identifier: #VU22540
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-18425
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to missing descriptor table limit checking in x86 PV emulation. A remote unprivileged user of a guest operating system can escalate privileges within the same guest system.
Note, only 32-bit PV guest is affected.
Affected software
Xen
Gentoo Linux
Debian Linux
Opensuse
Fedora
xen (Alpine package)
xen (Debian package)
xen
Gentoo Linux
Debian Linux
Opensuse
Fedora
xen (Alpine package)
xen (Debian package)
xen
How to mitigate CVE-2019-18425
Applying the appropriate attached patch resolves this issue. xsa298.patch xen-unstable, Xen 4.12.x xsa298-4.11.patch Xen 4.11.x xsa298-4.10.patch Xen 4.10.x xsa298-4.9.patch Xen 4.9.x, Xen 4.8.x, Xen 4.7.x $ sha256sum xsa298* 82c6f626732f99711212155b280270fe2f6683460299b1a6fc3f70b3932970ce xsa298.meta 3f422ad83abb54fe6afed460a5982cf1faa1717e51ab19fbf2375be1b5f8f4a3 xsa298.patch da8d5bad97a46c072dd1715c96401b145cecda14f0303043e6dca313e7ffff0c xsa298-4.9.patch 92dba14b6a208379c2569b9c1c11438da384ec47db2508b4761af30d74a9403d xsa298-4.10.patch d2d8eb5de5601b88f2a6503ecf6bb83207e4b2f17833d61a74fcd185ac7f5a71 xsa298-4.11.patch $
xen (Alpine package) - update to 4.10.4-r1
xen (Debian package) - addressed in versions 4.8.5.final+shim4.10.4-1+deb9u12, 4.11.3+24-g14b62ab3e5-1~deb10u1
xen - addressed in versions 4.11.2-2.fc29, 4.11.2-2.fc30, 4.11.2-3.fc30, 4.12.1-4.fc31, 4.12.1-5.fc31, 4.12.1-6.fc31
xen (Debian package) - addressed in versions 4.8.5.final+shim4.10.4-1+deb9u12, 4.11.3+24-g14b62ab3e5-1~deb10u1
xen - addressed in versions 4.11.2-2.fc29, 4.11.2-2.fc30, 4.11.2-3.fc30, 4.12.1-4.fc31, 4.12.1-5.fc31, 4.12.1-6.fc31
External References
Related Security Bulletins
- Multiple vulnerabilities in Xen
- OpenSUSE Linux update for xen
- Permissions, Privileges, and Access Controls in xen (Alpine package)
- Gentoo update for Xen
- Debian update for xen
- Fedora 31 update for xen
- Fedora 30 update for xen
- Fedora 29 update for xen
- Fedora 31 update for xen
- Fedora 30 update for xen
- Fedora 31 update for xen