CVE-2019-18424
published 2019-10-31CVE-2019-18424: An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a…
PriorityP430medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.50%
39.7th percentile
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to program the device to DMA to an arbitrary address. The IOMMU is used to protect the host from malicious DMA by making sure that the device addresses can only target memory assigned to the guest. However, when the guest domain is torn down, or the device is deassigned, the device is assigned back to dom0, thus allowing any in-flight DMA to potentially target critical host data. An untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation. Only systems where guests are given direct access to physical devices capable of DMA (PCI pass-through) are vulnerable. Systems which do not use PCI pass-through are not vulnerable.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.11.3+24-g14b62ab3e5-1 (bookworm) | xen 4.11.3+24-g14b62ab3e5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| xen | xen | <= 4.12.1 | — |
| xen | xen | >= 0 < 4.11.3+24-g14b62ab3e5-1 | 4.11.3+24-g14b62ab3e5-1 |
| xen | xen | >= 0 < 4.11.3+24-g14b62ab3e5-1 | 4.11.3+24-g14b62ab3e5-1 |
| xen | xen | >= 0 < 4.11.3+24-g14b62ab3e5-1 | 4.11.3+24-g14b62ab3e5-1 |
| xen | xen | >= 0 < 4.11.3+24-g14b62ab3e5-1 | 4.11.3+24-g14b62ab3e5-1 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation
vendor_redhat·2019-12-06·CVSS 6.8
CVE-2019-19579 [MEDIUM] CWE-266 xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation
xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in
Red Hat
xen: passed through PCI devices may corrupt host memory after deassignment leading to privilege escalation
vendor_redhat·2019-10-31·CVSS 6.8
CVE-2019-18424 [MEDIUM] CWE-284 xen: passed through PCI devices may corrupt host memory after deassignment leading to privilege escalation
xen: passed through PCI devices may corrupt host memory after deassignment leading to privilege escalation
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to program the device to DMA to an arbitrary address. The IOMMU is used to protect the host from malicious DMA by making sure that the device addresses can only target memory assigned to the guest. However, when the guest domain is torn down, or the device is deassigned, the device is assigned back to dom0, thus allowing any in-flight DMA t
Debian
CVE-2019-18424: xen - An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS...
vendor_debian·2019·CVSS 6.8
CVE-2019-18424 [MEDIUM] CVE-2019-18424: xen - An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS...
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to program the device to DMA to an arbitrary address. The IOMMU is used to protect the host from malicious DMA by making sure that the device addresses can only target memory assigned to the guest. However, when the guest domain is torn down, or the device is deassigned, the device is assigned back to dom0, thus allowing any in-flight DMA to potentially target critical host data. An untrusted domain with access to a physical device can DMA into h
Debian
CVE-2019-19579: xen - An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS...
vendor_debian·2019·CVSS 6.8
CVE-2019-19579 [MEDIUM] CVE-2019-19579: xen - An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS...
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device ca
GHSA
GHSA-3q68-jh6h-39cm: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24
CVE-2019-18424 [MEDIUM] CWE-78 GHSA-3q68-jh6h-39cm: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to program the device to DMA to an arbitrary address. The IOMMU is used to protect the host from malicious DMA by making sure that the device addresses can only target memory assigned to the guest. However, when the guest domain is torn down, or the device is deassigned, the device is assigned back to dom0, thus allowing any in-flight DMA to potentially target critical host data. An untrusted domain with access to a physical device can DMA into h
GHSA
GHSA-mw9v-9fv9-jf3f: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24·CVSS 6.8
CVE-2019-19579 [MEDIUM] GHSA-mw9v-9fv9-jf3f: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device ca
OSV
CVE-2019-19579: An issue was discovered in Xen through 4
osv·2019-12-04·CVSS 6.8
CVE-2019-19579 [MEDIUM] CVE-2019-19579: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device ca
OSV
CVE-2019-18424: An issue was discovered in Xen through 4
osv·2019-10-31·CVSS 6.8
CVE-2019-18424 [MEDIUM] CVE-2019-18424: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to program the device to DMA to an arbitrary address. The IOMMU is used to protect the host from malicious DMA by making sure that the device addresses can only target memory assigned to the guest. However, when the guest domain is torn down, or the device is deassigned, the device is assigned back to dom0, thus allowing any in-flight DMA to potentially target critical host data. An untrusted domain with access to a physical device can DMA into h
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18424 xen: passed through PCI devices may corrupt host memory after deassignment leading to privilege escalation [fedora-all]
bugzilla·2019-11-01·CVSS 6.8
CVE-2019-18424 [MEDIUM] CVE-2019-18424 xen: passed through PCI devices may corrupt host memory after deassignment leading to privilege escalation [fedora-all]
CVE-2019-18424 xen: passed through PCI devices may corrupt host memory after deassignment leading to privilege escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2019-18424 xen: passed through PCI devices may corrupt host memory after deassignment leading to privilege escalation
bugzilla·2019-11-01·CVSS 6.8
CVE-2019-18424 [MEDIUM] CVE-2019-18424 xen: passed through PCI devices may corrupt host memory after deassignment leading to privilege escalation
CVE-2019-18424 xen: passed through PCI devices may corrupt host memory after deassignment leading to privilege escalation
When a PCI device is assigned to an untrusted domain, it is possible for that domain to program the device to DMA to an arbitrary address. The IOMMU is used to protect the host from malicious DMA by making sure that the device addresses can only target memory assigned to the guest. However, when the guest domain is torn down the device is assigned back to dom0, thus allowing any in-flight DMA to potentially target critical host data.
Source: Xen Security Team
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1767731]
---
External References:
http://xenbits.xen.org/xsa/advisory-302.html
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00037.htmlhttp://www.openwall.com/lists/oss-security/2019/10/31/6http://xenbits.xen.org/xsa/advisory-302.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2BQKX7M2RHCWDBKNPX4KEBI3MJIH6AYZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5WWPW4BSZDDW7VHU427XTVXV7ROOFFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IZYATWNUGHRBG6I3TC24YHP5Y3J7I6KH/https://seclists.org/bugtraq/2020/Jan/21https://security.gentoo.org/glsa/202003-56https://www.debian.org/security/2020/dsa-4602http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00037.htmlhttp://www.openwall.com/lists/oss-security/2019/10/31/6http://xenbits.xen.org/xsa/advisory-302.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2BQKX7M2RHCWDBKNPX4KEBI3MJIH6AYZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5WWPW4BSZDDW7VHU427XTVXV7ROOFFW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IZYATWNUGHRBG6I3TC24YHP5Y3J7I6KH/https://seclists.org/bugtraq/2020/Jan/21https://security.gentoo.org/glsa/202003-56https://www.debian.org/security/2020/dsa-4602
2019-10-31
Published