CVE-2019-17351
published 2019-10-08CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of…
PriorityP424medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.41%
33.6th percentile
An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef36ab967c7.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.2.6-1 (bookworm) | linux 5.2.6-1 (bookworm) |
| linux | linux_kernel | < 5.2.3 | 5.2.3 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 5.2.6-1 | 5.2.6-1 |
| linux | linux_kernel | >= 0 < 4.4.0-174.204 | 4.4.0-174.204 |
| xen | xen | <= 4.12.1 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-02-18·CVSS 5.5
CVE-2019-14615 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the Linux kernel did not properly clear data
structures on context switches for certain Intel graphics processors. A
local attacker could use this to expose sensitive information.
(CVE-2019-14615)
It was discovered that a race condition existed in the Softmac USB Prism54
device driver in the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash). (CVE-2019-15220)
Julien Grall discovered that the Xen balloon memory driver in the Linux
kernel did not properly restrict the amount of memory set aside for page
mappings in some situations. An attacker could use this to cause a denial
of service (kernel memory exhaustion)
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2020-02-18·CVSS 5.5
CVE-2019-14615 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-4286-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM.
It was discovered that the Linux kernel did not properly clear data
structures on context switches for certain Intel graphics processors. A
local attacker could use this to expose sensitive information.
(CVE-2019-14615)
It was discovered that a race condition existed in the Softmac USB Prism54
device driver in the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash). (CVE-2019-15220)
Julien Grall discovered that
Red Hat
xen: no grant table and foreign mapping limits leading to crash and DoS
vendor_redhat·2019-07-22·CVSS 6.5
CVE-2019-17351 [MEDIUM] CWE-400 xen: no grant table and foreign mapping limits leading to crash and DoS
xen: no grant table and foreign mapping limits leading to crash and DoS
An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef36ab967c7.
Package: xen (Red Hat Enterprise Linux 5) - Out of support scope
Debian
CVE-2019-17351: linux - An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2....
vendor_debian·2019·CVSS 6.5
CVE-2019-17351 [MEDIUM] CVE-2019-17351: linux - An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2....
An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef36ab967c7.
Scope: local
bookworm: resolved (fixed in 5.2.6-1)
bullseye: resolved (fixed in 5.2.6-1)
forky: resolved (fixed in 5.2.6-1)
sid: resolved (fixed in 5.2.6-1)
trixie: resolved (fixed in 5.2.6-1)
GHSA
GHSA-p22j-6g62-hrrp: An issue was discovered in drivers/xen/balloon
ghsa_unreviewed·2022-05-24
CVE-2019-17351 [MEDIUM] GHSA-p22j-6g62-hrrp: An issue was discovered in drivers/xen/balloon
An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef36ab967c7.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2020-02-18·CVSS 5.5
CVE-2019-14615 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the Linux kernel did not properly clear data
structures on context switches for certain Intel graphics processors. A
local attacker could use this to expose sensitive information.
(CVE-2019-14615)
It was discovered that a race condition existed in the Softmac USB Prism54
device driver in the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash). (CVE-2019-15220)
Julien Grall discovered that the Xen balloon memory driver in the Linux
kernel did not properly restrict the amount of memory set aside for page
mappings in some situations. An attacker could use this to cause a denial
of service (kernel memory exhaustion). (CVE-2019-17351)
It was
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2020-02-18·CVSS 5.5
CVE-2019-14615 [MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-4286-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM.
It was discovered that the Linux kernel did not properly clear data
structures on context switches for certain Intel graphics processors. A
local attacker could use this to expose sensitive information.
(CVE-2019-14615)
It was discovered that a race condition existed in the Softmac USB Prism54
device driver in the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash). (CVE-2019-15220)
Julien Grall discovered that the Xen balloon memory driver in the Linux
kernel did not properly rest
OSV
CVE-2019-17351: An issue was discovered in drivers/xen/balloon
osv·2019-10-08·CVSS 6.5
CVE-2019-17351 [MEDIUM] CVE-2019-17351: An issue was discovered in drivers/xen/balloon
An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef36ab967c7.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2019/10/25/9http://xenbits.xen.org/xsa/advisory-300.htmlhttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3https://github.com/torvalds/linux/commit/6ef36ab967c71690ebe7e5ef997a8be4da3bc844https://security.netapp.com/advisory/ntap-20191031-0005/https://usn.ubuntu.com/4286-1/https://usn.ubuntu.com/4286-2/https://xenbits.xen.org/xsa/advisory-300.htmlhttp://www.openwall.com/lists/oss-security/2019/10/25/9http://xenbits.xen.org/xsa/advisory-300.htmlhttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3https://github.com/torvalds/linux/commit/6ef36ab967c71690ebe7e5ef997a8be4da3bc844https://security.netapp.com/advisory/ntap-20191031-0005/https://usn.ubuntu.com/4286-1/https://usn.ubuntu.com/4286-2/https://xenbits.xen.org/xsa/advisory-300.html
2019-10-08
Published