Input validation error in Xen - CVE-2019-18420
Published: November 6, 2019
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the VCPUOP_initialise hypercall in Xen. A remote user on a guest operating system can run a specially crafted program and perform a denial of service attack against the host operating system.
Affected software
Debian Linux
Gentoo Linux
Opensuse
Fedora
xen (Alpine package)
xen (Debian package)
xen
How to mitigate CVE-2019-18420
xsa296.patch Xen 4.9 ... unstable xsa296-4.8.patch Xen 4.7 ... 4.8 $ sha256sum xsa296* 71bd433f788dd511fad90165bc5ba9bcabe949eecd912f2a616e3c996960d67d xsa296.meta ccfd81b162b8535d952f56b1f87dfdd960e71bf07c1cf8388976e78e2e86cde5 xsa296.patch b283be3df6789402553172b7fd582bfffb4fa72a6b33543439bd2fb1b87bfbd4 xsa296-4.8.patch $
xen - addressed in versions 4.11.2-2.fc29, 4.11.2-2.fc30, 4.11.2-3.fc30, 4.12.1-4.fc31, 4.12.1-5.fc31, 4.12.1-6.fc31
External References
Related Security Bulletins
- Multiple vulnerabilities in Xen
- OpenSUSE Linux update for xen
- Input validation error in xen (Alpine package)
- Gentoo update for Xen
- Debian update for xen
- Fedora 31 update for xen
- Fedora 30 update for xen
- Fedora 29 update for xen
- Fedora 31 update for xen
- Fedora 30 update for xen
- Fedora 31 update for xen