CVE-2019-17341
published 2019-10-08CVE-2019-17341: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability…
PriorityP336high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.26%
17.5th percentile
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.11.1+92-g6c33308a8d-1 (bookworm) | xen 4.11.1+92-g6c33308a8d-1 (bookworm) |
| xen | xen | <= 4.11.2 | — |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: xsa285: race with pass-through device hotplug
vendor_redhat·2019-03-05·CVSS 7.8
CVE-2019-17341 [HIGH] CWE-362 xen: xsa285: race with pass-through device hotplug
xen: xsa285: race with pass-through device hotplug
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2019-17341: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
vendor_debian·2019·CVSS 7.8
CVE-2019-17341 [HIGH] CVE-2019-17341: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
sid: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
trixie: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
GHSA
GHSA-6xww-266g-3f8v: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24
CVE-2019-17341 [HIGH] CWE-362 GHSA-6xww-266g-3f8v: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
OSV
CVE-2019-17341: An issue was discovered in Xen through 4
osv·2019-10-08·CVSS 7.8
CVE-2019-17341 [HIGH] CVE-2019-17341: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2019/10/25/6http://xenbits.xen.org/xsa/advisory-285.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-285.htmlhttp://www.openwall.com/lists/oss-security/2019/10/25/6http://xenbits.xen.org/xsa/advisory-285.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-285.html
2019-10-08
Published