CVE-2019-17344
published 2019-10-08CVE-2019-17344: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to…
PriorityP422medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.35%
27.2th percentile
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.11.1+92-g6c33308a8d-1 (bookworm) | xen 4.11.1+92-g6c33308a8d-1 (bookworm) |
| xen | xen | <= 4.11.2 | — |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: xsa290: missing preemption in x86 PV page table unvalidation
vendor_redhat·2019-03-05·CVSS 6.5
CVE-2019-17344 [MEDIUM] CWE-400 xen: xsa290: missing preemption in x86 PV page table unvalidation
xen: xsa290: missing preemption in x86 PV page table unvalidation
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2019-17344: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
vendor_debian·2019·CVSS 6.5
CVE-2019-17344 [MEDIUM] CVE-2019-17344: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
sid: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
trixie: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
GHSA
GHSA-q4jv-8wfr-4pf8: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24
CVE-2019-17344 [MEDIUM] CWE-20 GHSA-q4jv-8wfr-4pf8: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates.
OSV
CVE-2019-17344: An issue was discovered in Xen through 4
osv·2019-10-08·CVSS 6.5
CVE-2019-17344 [MEDIUM] CVE-2019-17344: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2019/10/25/3http://xenbits.xen.org/xsa/advisory-290.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-290.htmlhttp://www.openwall.com/lists/oss-security/2019/10/25/3http://xenbits.xen.org/xsa/advisory-290.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-290.html
2019-10-08
Published