cbcvebase.
CVE-2018-19962
published 2018-12-08

CVE-2018-19962: An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings…

high7.8CVSS 3.0
AVLACHPRLUINSCCHIHAH
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

Affected

18 ranges
VendorProductVersion rangeFixed in
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debiandebian_linux
debianxen< xen 4.11.1-1 (bookworm)xen 4.11.1-1 (bookworm)
xenxen<= 4.11.1
xenxen>= 0 < 4.11.1-14.11.1-1
xenxen>= 0 < 4.11.1-14.11.1-1
xenxen>= 0 < 4.11.1-14.11.1-1
xenxen>= 0 < 4.11.1-14.11.1-1

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
osv7.8HIGH