CVE-2018-10981
published 2018-05-10CVE-2018-10981: An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU…
PriorityP422medium6.5CVSS 3.0
AVLACLPRLUINSCCNINAH
EPSS
0.44%
36.2th percentile
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm) | xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm) |
| xen | xen | <= 4.10.1 | — |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: qemu may drive Xen into unbounded loop (XSA-262)
vendor_redhat·2018-05-08·CVSS 6.5
CVE-2018-10981 [MEDIUM] xen: qemu may drive Xen into unbounded loop (XSA-262)
xen: qemu may drive Xen into unbounded loop (XSA-262)
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2018-10981: xen - An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to...
vendor_debian·2018·CVSS 6.5
CVE-2018-10981 [MEDIUM] CVE-2018-10981: xen - An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to...
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.
Scope: local
bookworm: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
bullseye: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
forky: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
sid: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
trixie: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
GHSA
GHSA-g85j-48pg-m4xc: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-13
CVE-2018-10981 [MEDIUM] CWE-835 GHSA-g85j-48pg-m4xc: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.
OSV
CVE-2018-10981: An issue was discovered in Xen through 4
osv·2018-05-10·CVSS 6.5
CVE-2018-10981 [MEDIUM] CVE-2018-10981: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.
No detection rules found.
No public exploits indexed.
http://openwall.com/lists/oss-security/2018/05/08/3http://www.securityfocus.com/bid/104149https://lists.debian.org/debian-lts-announce/2018/05/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/10/msg00021.htmlhttps://security.gentoo.org/glsa/201810-06https://www.debian.org/security/2018/dsa-4201https://xenbits.xen.org/xsa/advisory-262.htmlhttp://openwall.com/lists/oss-security/2018/05/08/3http://www.securityfocus.com/bid/104149https://lists.debian.org/debian-lts-announce/2018/05/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/10/msg00021.htmlhttps://security.gentoo.org/glsa/201810-06https://www.debian.org/security/2018/dsa-4201https://xenbits.xen.org/xsa/advisory-262.html
2018-05-10
Published