CVE-2018-10982
published 2018-05-10CVE-2018-10982: An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun…
PriorityP337high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.49%
38.8th percentile
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm) | xen 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 (bookworm) |
| xen | xen | <= 4.10.1 | — |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
| xen | xen | >= 0 < 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 | 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c292-2j32-cgq5: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-13
CVE-2018-10982 [HIGH] GHSA-c292-2j32-cgq5: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.
OSV
CVE-2018-10982: An issue was discovered in Xen through 4
osv·2018-05-10·CVSS 8.8
CVE-2018-10982 [HIGH] CVE-2018-10982: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.
Red Hat
xen: x86 vHPET interrupt injection errors (XSA-261)
vendor_redhat·2018-05-08·CVSS 8.8
CVE-2018-10982 [HIGH] xen: x86 vHPET interrupt injection errors (XSA-261)
xen: x86 vHPET interrupt injection errors (XSA-261)
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2018-10982: xen - An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to...
vendor_debian·2018·CVSS 8.8
CVE-2018-10982 [HIGH] CVE-2018-10982: xen - An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to...
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.
Scope: local
bookworm: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
bullseye: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
forky: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
sid: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
trixie: resolved (fixed in 4.8.3+xsa262+shim4.10.0+comet3-1+deb9u6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10982 xsa261 xen: x86 vHPET interrupt injection errors (XSA-261)
bugzilla·2018-04-25·CVSS 8.8
CVE-2018-10982 [HIGH] CVE-2018-10982 xsa261 xen: x86 vHPET interrupt injection errors (XSA-261)
CVE-2018-10982 xsa261 xen: x86 vHPET interrupt injection errors (XSA-261)
ISSUE DESCRIPTION
The High Precision Event Timer (HPET) can be configured to deliver
interrupts in one of three different modes - through legacy interrupts;
through the IO-APIC; or optionally via a method similar to PCI MSI. The
last mode is optional and not implemented by Xen. However, of the first
two modes, only the legacy variant was properly implemented.
If a guest set up an HPET timer in IO-APIC mode, Xen would still
handle this using the code for the legacy mode. Unfortunately, the
available IO-APIC mode interrupt numbers are higher than legacy mode
interrupts. The result was array overruns.
IMPACT
A malicious or buggy HVM guest may cause a hypervisor crash, resulting
in a Denial of Service (DoS) affectin
arXiv
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
arxiv_fulltext·2025-06-11
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond
: Is Your "Clean" Vulnerability Dataset Really Solvable?
Exposing and Trapping Undecidable Patches and Beyond
@IEEEauthorhalign
@IEEEauthorhalign
Zeyu Gao1 1Equal contribution
Tsinghua University
[email protected]
Junlin Zhou1
Sichuan University
[email protected]
Bolun Zhang
Institute of Information Engineering,
Chinese Academy of Sciences
[email protected]
Yi He
Wuhan University
[email protected]
Chao Zhang22Corresponding author
Tsinghua University
[email protected]
Yuxin Cui
Tsinghua University
[email protected]
Hao Wang
Tsinghua University
[email protected]
## Abstract
The quantity and quality of vulnerability datasets are essential for developing deep learning solutions to vulnerability-related tasks. Due
http://openwall.com/lists/oss-security/2018/05/08/2http://www.securityfocus.com/bid/104150https://lists.debian.org/debian-lts-announce/2018/05/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/10/msg00009.htmlhttps://security.gentoo.org/glsa/201810-06https://www.debian.org/security/2018/dsa-4201https://xenbits.xen.org/xsa/advisory-261.htmlhttp://openwall.com/lists/oss-security/2018/05/08/2http://www.securityfocus.com/bid/104150https://lists.debian.org/debian-lts-announce/2018/05/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2018/10/msg00009.htmlhttps://security.gentoo.org/glsa/201810-06https://www.debian.org/security/2018/dsa-4201https://xenbits.xen.org/xsa/advisory-261.html
2018-05-10
Published