cbcvebase.
CVE-2018-19965
published 2018-12-08

CVE-2018-19965: An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a…

medium5.6CVSS 3.0
AVLACHPRLUINSCCNINAH
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.

Affected

18 ranges
VendorProductVersion rangeFixed in
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debiandebian_linux
debianxen< xen 4.11.1-1 (bookworm)xen 4.11.1-1 (bookworm)
xenxen<= 4.11.1
xenxen>= 0 < 4.11.1-14.11.1-1
xenxen>= 0 < 4.11.1-14.11.1-1
xenxen>= 0 < 4.11.1-14.11.1-1
xenxen>= 0 < 4.11.1-14.11.1-1

CVSS provenance

nvdv3.05.6MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
osv5.6MEDIUM