CVE-2018-7542
published 2018-02-27CVE-2018-7542: An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor…
PriorityP420medium6.5CVSS 3.0
AVLACLPRLUINSCCNINAH
EPSS
0.39%
31.2th percentile
An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 (bookworm) | xen 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 (bookworm) |
| xen | xen | >= 0 < 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 | 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 |
| xen | xen | >= 0 < 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 | 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 |
| xen | xen | >= 0 < 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 | 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 |
| xen | xen | >= 0 < 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 | 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 |
| xen | xen | 4.8.0 – 4.10.0 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: x86 PVH guest without LAPIC may DoS the host (XSA-256)
vendor_redhat·2018-02-27·CVSS 6.5
CVE-2018-7542 [MEDIUM] xen: x86 PVH guest without LAPIC may DoS the host (XSA-256)
xen: x86 PVH guest without LAPIC may DoS the host (XSA-256)
An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2018-7542: xen - An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS us...
vendor_debian·2018·CVSS 6.5
CVE-2018-7542 [MEDIUM] CVE-2018-7542: xen - An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS us...
An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.
Scope: local
bookworm: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
bullseye: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
forky: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
sid: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
trixie: resolved (fixed in 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5)
GHSA
GHSA-3958-x3r2-xc87: An issue was discovered in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2018-7542 [MEDIUM] CWE-476 GHSA-3958-x3r2-xc87: An issue was discovered in Xen 4
An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.
OSV
CVE-2018-7542: An issue was discovered in Xen 4
osv·2018-02-27·CVSS 6.5
CVE-2018-7542 [MEDIUM] CVE-2018-7542: An issue was discovered in Xen 4
An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-7542 xen: xsa256 xen: x86 PVH guest without LAPIC may DoS the host (XSA-256) [fedora-all]
bugzilla·2018-02-27·CVSS 6.5
CVE-2018-7542 [MEDIUM] CVE-2018-7542 xen: xsa256 xen: x86 PVH guest without LAPIC may DoS the host (XSA-256) [fedora-all]
CVE-2018-7542 xen: xsa256 xen: x86 PVH guest without LAPIC may DoS the host (XSA-256) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2018-7542 xsa256 xen: x86 PVH guest without LAPIC may DoS the host (XSA-256)
bugzilla·2018-02-12·CVSS 6.5
CVE-2018-7542 [MEDIUM] CVE-2018-7542 xsa256 xen: x86 PVH guest without LAPIC may DoS the host (XSA-256)
CVE-2018-7542 xsa256 xen: x86 PVH guest without LAPIC may DoS the host (XSA-256)
ISSUE DESCRIPTION
So far, x86 PVH guests can be configured with or without Local APICs.
Configurations with Local APICs are identical to x86 HVM guests, and
will use as much hardware acceleration support as possible.
Configurations without Local APICs try to turn off all hardware
acceleration, and disable all software emulation.
Multiple paths in Xen assume the presence of a Local APIC without
sufficient checks, and can fall over a NULL pointer. On Intel hardware,
the logic to turn off hardware acceleration is incomplete and leaves the
guest with full control of the real Task Priority Register.
IMPACT
A malicious or buggy guest may cause a hypervisor crash, resulting in
a Denial of Service (DoS) affecting
http://www.securitytracker.com/id/1040776https://security.gentoo.org/glsa/201810-06https://www.debian.org/security/2018/dsa-4131https://xenbits.xen.org/xsa/advisory-256.htmlhttp://www.securitytracker.com/id/1040776https://security.gentoo.org/glsa/201810-06https://www.debian.org/security/2018/dsa-4131https://xenbits.xen.org/xsa/advisory-256.html
2018-02-27
Published