cbcvebase.
CVE-2018-19961
published 2018-12-08

CVE-2018-19961: An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not…

high7.8CVSS 3.0
AVLACHPRLUINSCCHIHAH
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.

Affected

18 ranges
VendorProductVersion rangeFixed in
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debiandebian_linux
debianxen< xen 4.11.1-1 (bookworm)xen 4.11.1-1 (bookworm)
xenxen<= 4.11.1
xenxen>= 0 < 4.11.1-14.11.1-1
xenxen>= 0 < 4.11.1-14.11.1-1
xenxen>= 0 < 4.11.1-14.11.1-1
xenxen>= 0 < 4.11.1-14.11.1-1

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
osv7.8HIGH