CVE-2019-17346
published 2019-10-08CVE-2019-17346: An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility…
PriorityP339high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.35%
27.4th percentile
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.11.1+92-g6c33308a8d-1 (bookworm) | xen 4.11.1+92-g6c33308a8d-1 (bookworm) |
| xen | xen | <= 4.11.2 | — |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
| xen | xen | >= 0 < 4.11.1+92-g6c33308a8d-1 | 4.11.1+92-g6c33308a8d-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: xsa292: insufficient TLB flushing when using PCID
vendor_redhat·2019-03-05·CVSS 8.8
CVE-2019-17346 [HIGH] CWE-400 xen: xsa292: insufficient TLB flushing when using PCID
xen: xsa292: insufficient TLB flushing when using PCID
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2019-17346: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
vendor_debian·2019·CVSS 8.8
CVE-2019-17346 [HIGH] CVE-2019-17346: xen - An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.
Scope: local
bookworm: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
bullseye: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
forky: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
sid: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
trixie: resolved (fixed in 4.11.1+92-g6c33308a8d-1)
GHSA
GHSA-j897-36j5-vg2q: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24
CVE-2019-17346 [HIGH] CWE-20 GHSA-j897-36j5-vg2q: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.
OSV
CVE-2019-17346: An issue was discovered in Xen through 4
osv·2019-10-08·CVSS 8.8
CVE-2019-17346 [HIGH] CVE-2019-17346: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2019/10/25/5http://xenbits.xen.org/xsa/advisory-292.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-292.htmlhttp://www.openwall.com/lists/oss-security/2019/10/25/5http://xenbits.xen.org/xsa/advisory-292.htmlhttps://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://xenbits.xen.org/xsa/advisory-292.html
2019-10-08
Published