CVE-2019-17345
published 2019-10-08CVE-2019-17345: An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations…
PriorityP422medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.35%
27.2th percentile
An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations causes a bug check during the cleanup of a crashed guest.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.11.1+92-g6c33308a8d-1 (bookworm) | xen 4.11.1+92-g6c33308a8d-1 (bookworm) |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | 4.8.0 – 4.11.2 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ph73-rj9x-9q3g: An issue was discovered in Xen 4
ghsa_unreviewed·2022-05-24
CVE-2019-17345 [MEDIUM] CWE-20 GHSA-ph73-rj9x-9q3g: An issue was discovered in Xen 4
An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations causes a bug check during the cleanup of a crashed guest.
OSV
CVE-2019-17345: An issue was discovered in Xen 4
osv·2019-10-08·CVSS 6.5
CVE-2019-17345 [MEDIUM] CVE-2019-17345: An issue was discovered in Xen 4
An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations causes a bug check during the cleanup of a crashed guest.
Red Hat
xen: xsa291: x86/PV: page type reference counting issue with failed IOMMU update
vendor_redhat·2019-03-05·CVSS 6.5
CVE-2019-17345 [MEDIUM] xen: xsa291: x86/PV: page type reference counting issue with failed IOMMU update
xen: xsa291: x86/PV: page type reference counting issue with failed IOMMU update
An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations causes a bug check during the cleanup of a crashed guest.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2019-17345: xen - An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS use...
vendor_debian·2019·CVSS 6.5
CVE-2019-17345 [MEDIUM] CVE-2019-17345: xen - An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS use...
An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations causes a bug check during the cleanup of a crashed guest.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
sid: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
trixie: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2019/10/25/4http://xenbits.xen.org/xsa/advisory-291.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-291.htmlhttp://www.openwall.com/lists/oss-security/2019/10/25/4http://xenbits.xen.org/xsa/advisory-291.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-291.html
2019-10-08
Published