CVE-2018-10471
published 2018-04-27CVE-2018-10471: An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via…
PriorityP423medium6.5CVSS 3.0
AVLACLPRLUINSCCNINAH
EPSS
0.43%
34.8th percentile
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm) | xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm) |
| xen | xen | <= 4.10.1 | — |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: x86 PV guest may crash Xen with XPTI
vendor_redhat·2018-04-25·CVSS 5.6
CVE-2018-10471 [MEDIUM] CWE-787 xen: x86 PV guest may crash Xen with XPTI
xen: x86 PV guest may crash Xen with XPTI
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
An OOB write issue was found in the way Xen hypervisor handled error in the Page Table Isolation (PTI) implementation, used to fix the Meltdown issue. It could occur while processing interrupt 'INT 0x80', when PV guest's vCPU has no handler for it. A malicious guest user/process could use this flaw to crash the hypervisor resulting in denial of service issue.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2018-10471: xen - An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to ...
vendor_debian·2018·CVSS 5.6
CVE-2018-10471 [MEDIUM] CVE-2018-10471: xen - An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
Scope: local
bookworm: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
bullseye: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
forky: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
sid: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
trixie: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
GHSA
GHSA-v5vc-f4vf-8rvg: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-14·CVSS 5.6
CVE-2018-10471 [MEDIUM] CWE-787 GHSA-v5vc-f4vf-8rvg: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
OSV
CVE-2018-10471: An issue was discovered in Xen through 4
osv·2018-04-27·CVSS 5.6
CVE-2018-10471 [MEDIUM] CVE-2018-10471: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10471 xen: xsa259 xen: x86 PV guest may crash Xen with XPTI [fedora-all]
bugzilla·2018-04-25·CVSS 6.5
CVE-2018-10471 [MEDIUM] CVE-2018-10471 xen: xsa259 xen: x86 PV guest may crash Xen with XPTI [fedora-all]
CVE-2018-10471 xen: xsa259 xen: x86 PV guest may crash Xen with XPTI [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2018-10471 xsa259 xen: x86 PV guest may crash Xen with XPTI
bugzilla·2018-04-11·CVSS 6.5
CVE-2018-10471 [MEDIUM] CVE-2018-10471 xsa259 xen: x86 PV guest may crash Xen with XPTI
CVE-2018-10471 xsa259 xen: x86 PV guest may crash Xen with XPTI
ISSUE DESCRIPTION
The workaround for the Meltdown vulnerability (XSA-254) failed to deal
with an error code path connecting the INT 80 handling with general
exception handling. This results in an unconditional write attempt of
the value zero to an address near 2^64, in cases where a PV guest has no
handler installed for INT 80 on one of its vCPU-s.
IMPACT
A malicious or buggy guest may cause a hypervisor crash, resulting in
a Denial of Service (DoS) affecting the entire host.
VULNERABLE SYSTEMS
All Xen versions which the XSA-254 fixes were applied to are vulnerable.
Only x86 systems are vulnerable. ARM systems are not vulnerable.
Only x86 PV guests can exploit the vulnerability. x86 PVH and HVM
guests cannot exploit th
http://www.securityfocus.com/bid/104003https://lists.debian.org/debian-lts-announce/2018/10/msg00009.htmlhttps://security.gentoo.org/glsa/201810-06https://www.debian.org/security/2018/dsa-4201https://xenbits.xen.org/xsa/advisory-259.htmlhttp://www.securityfocus.com/bid/104003https://lists.debian.org/debian-lts-announce/2018/10/msg00009.htmlhttps://security.gentoo.org/glsa/201810-06https://www.debian.org/security/2018/dsa-4201https://xenbits.xen.org/xsa/advisory-259.html
2018-04-27
Published