CVE-2019-17343
published 2019-10-08CVE-2019-17343: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the…
PriorityP424medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.28%
20.1th percentile
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.11.1+92-g6c33308a8d-1 (bookworm) | xen 4.11.1+92-g6c33308a8d-1 (bookworm) |
| xen | xen | <= 4.11.2 | — |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: xsa288: Inconsistent PV IOMMU discipline
vendor_redhat·2019-03-05·CVSS 6.8
CVE-2019-17343 [MEDIUM] CWE-362 xen: xsa288: Inconsistent PV IOMMU discipline
xen: xsa288: Inconsistent PV IOMMU discipline
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2019-17343: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
vendor_debian·2019·CVSS 6.8
CVE-2019-17343 [MEDIUM] CVE-2019-17343: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
sid: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
trixie: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
GHSA
GHSA-4q76-cfmr-jqcp: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24
CVE-2019-17343 [MEDIUM] CWE-20 GHSA-4q76-cfmr-jqcp: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.
OSV
CVE-2019-17343: An issue was discovered in Xen through 4
osv·2019-10-08·CVSS 6.8
CVE-2019-17343 [MEDIUM] CVE-2019-17343: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2019/10/25/10http://xenbits.xen.org/xsa/advisory-288.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-288.htmlhttp://www.openwall.com/lists/oss-security/2019/10/25/10http://xenbits.xen.org/xsa/advisory-288.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-288.html
2019-10-08
Published