CVE-2018-19966
published 2018-12-08CVE-2018-19966: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges…
PriorityP339high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.44%
35.9th percentile
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.11.1-1 (bookworm) | xen 4.11.1-1 (bookworm) |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | >= 0 < 4.11.1-1 | 4.11.1-1 |
| xen | xen | 4.11.0 – 4.11.1 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3635-87f7-gfgj: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2018-19966 [HIGH] CWE-436 GHSA-3635-87f7-gfgj: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.
OSV
CVE-2018-19966: An issue was discovered in Xen through 4
osv·2018-12-08·CVSS 8.8
CVE-2018-19966 [HIGH] CVE-2018-19966: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.
Red Hat
xen: Conflicts with shadow paging due to XSA-240 incomplete fix (XSA-280)
vendor_redhat·2018-11-20·CVSS 8.8
CVE-2018-19966 [HIGH] CWE-770 xen: Conflicts with shadow paging due to XSA-240 incomplete fix (XSA-280)
xen: Conflicts with shadow paging due to XSA-240 incomplete fix (XSA-280)
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2018-19966: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
vendor_debian·2018·CVSS 8.8
CVE-2018-19966 [HIGH] CVE-2018-19966: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.
Scope: local
bookworm: resolved (fixed in 4.11.1-1)
bullseye: resolved (fixed in 4.11.1-1)
forky: resolved (fixed in 4.11.1-1)
sid: resolved (fixed in 4.11.1-1)
trixie: resolved (fixed in 4.11.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-19966 xsa280 xen: Conflicts with shadow paging due to XSA-240 incomplete fix (XSA-280)
bugzilla·2018-11-21·CVSS 8.8
CVE-2018-19966 [HIGH] CVE-2018-19966 xsa280 xen: Conflicts with shadow paging due to XSA-240 incomplete fix (XSA-280)
CVE-2018-19966 xsa280 xen: Conflicts with shadow paging due to XSA-240 incomplete fix (XSA-280)
ISSUE DESCRIPTION
The fix for XSA-240 introduced a new field into the control structure
associated with each page of RAM. This field was added to a union,
another member of which is used when Xen uses shadow paging for the
guest. During migration, or with the L1TF (XSA-273) mitigation for
PV guests in effect, the two uses conflict.
IMPACT
A malicious or buggy x86 PV guest may cause Xen to crash, resulting in
a DoS (Denial of Service) affecting the entire host. Privilege
escalation as well as information leaks cannot be ruled out.
VULNERABLE SYSTEMS
All Xen versions from at least 3.2 onwards are vulnerable. Earlier
versions have not been checked.
Only x86 systems are affected. ARM systems
Bugzilla
CVE-2018-19963 CVE-2018-19964 CVE-2018-19966 xen: various flaws [fedora-all]
bugzilla·2018-11-21·CVSS 7.8
CVE-2018-19963 [HIGH] CVE-2018-19963 CVE-2018-19964 CVE-2018-19966 xen: various flaws [fedora-all]
CVE-2018-19963 CVE-2018-19964 CVE-2018-19966 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.htmlhttp://www.securityfocus.com/bid/106182https://lists.debian.org/debian-lts-announce/2019/10/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXC6BME7SXJI2ZIATNXCAH7RGPI4UKTT/https://www.debian.org/security/2019/dsa-4369https://xenbits.xen.org/xsa/advisory-280.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.htmlhttp://www.securityfocus.com/bid/106182https://lists.debian.org/debian-lts-announce/2019/10/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXC6BME7SXJI2ZIATNXCAH7RGPI4UKTT/https://www.debian.org/security/2019/dsa-4369https://xenbits.xen.org/xsa/advisory-280.html
2018-12-08
Published