CVE-2018-19965
published 2018-12-08CVE-2018-19965: An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a…
PriorityP420medium5.6CVSS 3.0
AVLACHPRLUINSCCNINAH
EPSS
0.41%
33.5th percentile
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.11.1-1 (bookworm) | xen 4.11.1-1 (bookworm) |
| xen | xen | <= 4.11.1 | — |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
CVSS provenance
nvdv3.05.6MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c3g2-qp55-6gjf: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-13·CVSS 5.6
CVE-2018-19965 [MEDIUM] GHSA-c3g2-qp55-6gjf: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.
OSV
CVE-2018-19965: An issue was discovered in Xen through 4
osv·2018-12-08·CVSS 5.6
CVE-2018-19965 [MEDIUM] CVE-2018-19965: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.
Red Hat
xen: x86: DoS from attempting to use INVPCID with a non-canonical addresses
vendor_redhat·2018-11-20·CVSS 5.6
CVE-2018-19965 [MEDIUM] CWE-228 xen: x86: DoS from attempting to use INVPCID with a non-canonical addresses
xen: x86: DoS from attempting to use INVPCID with a non-canonical addresses
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2018-19965: xen - An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users ...
vendor_debian·2018·CVSS 5.6
CVE-2018-19965 [MEDIUM] CVE-2018-19965: xen - An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users ...
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.
Scope: local
bookworm: resolved (fixed in 4.11.1-1)
bullseye: resolved (fixed in 4.11.1-1)
forky: resolved (fixed in 4.11.1-1)
sid: resolved (fixed in 4.11.1-1)
trixie: resolved (fixed in 4.11.1-1)
Citrix
Citrix Security Bulletin CTX239432
vendor_citrix·CVSS 7.8
CVE-2018-19961 [HIGH] Citrix Security Bulletin CTX239432
Citrix Security Bulletin CTX239432
CVE References: CVE-2018-19961, CVE-2018-19962, CVE-2018-19965, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.htmlhttp://www.securityfocus.com/bid/106182https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXC6BME7SXJI2ZIATNXCAH7RGPI4UKTT/https://support.citrix.com/article/CTX239432https://www.debian.org/security/2019/dsa-4369https://xenbits.xen.org/xsa/advisory-279.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.htmlhttp://www.securityfocus.com/bid/106182https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXC6BME7SXJI2ZIATNXCAH7RGPI4UKTT/https://support.citrix.com/article/CTX239432https://www.debian.org/security/2019/dsa-4369https://xenbits.xen.org/xsa/advisory-279.html
2018-12-08
Published