CVE-2018-19961
published 2018-12-08CVE-2018-19961: An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not…
PriorityP337high7.8CVSS 3.0
AVLACHPRLUINSCCHIHAH
EPSS
0.41%
33.1th percentile
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.11.1-1 (bookworm) | xen 4.11.1-1 (bookworm) |
| xen | xen | <= 4.11.1 | — |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: insufficient TLB flushing / improper large page mappings with AMD IOMMUs
vendor_redhat·2018-11-20·CVSS 7.8
CVE-2018-19961 [HIGH] CWE-212 xen: insufficient TLB flushing / improper large page mappings with AMD IOMMUs
xen: insufficient TLB flushing / improper large page mappings with AMD IOMMUs
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2018-19961: xen - An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly all...
vendor_debian·2018·CVSS 7.8
CVE-2018-19961 [HIGH] CVE-2018-19961: xen - An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly all...
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
Scope: local
bookworm: resolved (fixed in 4.11.1-1)
bullseye: resolved (fixed in 4.11.1-1)
forky: resolved (fixed in 4.11.1-1)
sid: resolved (fixed in 4.11.1-1)
trixie: resolved (fixed in 4.11.1-1)
Citrix
Citrix Security Bulletin CTX239432
vendor_citrix·CVSS 7.8
CVE-2018-19961 [HIGH] Citrix Security Bulletin CTX239432
Citrix Security Bulletin CTX239432
CVE References: CVE-2018-19961, CVE-2018-19962, CVE-2018-19965, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-qwxp-946x-p86v: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-13
CVE-2018-19961 [HIGH] CWE-459 GHSA-qwxp-946x-p86v: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
OSV
CVE-2018-19961: An issue was discovered in Xen through 4
osv·2018-12-08·CVSS 7.8
CVE-2018-19961 [HIGH] CVE-2018-19961: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.htmlhttp://www.securityfocus.com/bid/106182https://lists.debian.org/debian-lts-announce/2019/10/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXC6BME7SXJI2ZIATNXCAH7RGPI4UKTT/https://support.citrix.com/article/CTX239432https://www.debian.org/security/2019/dsa-4369https://xenbits.xen.org/xsa/advisory-275.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.htmlhttp://www.securityfocus.com/bid/106182https://lists.debian.org/debian-lts-announce/2019/10/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXC6BME7SXJI2ZIATNXCAH7RGPI4UKTT/https://support.citrix.com/article/CTX239432https://www.debian.org/security/2019/dsa-4369https://xenbits.xen.org/xsa/advisory-275.html
2018-12-08
Published