CVE-2019-19579
published 2019-12-04CVE-2019-19579: An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a…
PriorityP429medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.45%
36.4th percentile
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation. Only systems where guests are given direct access to physical devices capable of DMA (PCI pass-through) are vulnerable. Systems which do not use PCI pass-through are not vulnerable.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.11.3+24-g14b62ab3e5-1 (bookworm) | xen 4.11.3+24-g14b62ab3e5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| xen | xen | <= 4.12.1 | — |
| xen | xen | >= 0 < 4.11.3+24-g14b62ab3e5-1 | 4.11.3+24-g14b62ab3e5-1 |
| xen | xen | >= 0 < 4.11.3+24-g14b62ab3e5-1 | 4.11.3+24-g14b62ab3e5-1 |
| xen | xen | >= 0 < 4.11.3+24-g14b62ab3e5-1 | 4.11.3+24-g14b62ab3e5-1 |
| xen | xen | >= 0 < 4.11.3+24-g14b62ab3e5-1 | 4.11.3+24-g14b62ab3e5-1 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mw9v-9fv9-jf3f: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24·CVSS 6.8
CVE-2019-19579 [MEDIUM] GHSA-mw9v-9fv9-jf3f: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device ca
OSV
CVE-2019-19579: An issue was discovered in Xen through 4
osv·2019-12-04·CVSS 6.8
CVE-2019-19579 [MEDIUM] CVE-2019-19579: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device ca
Red Hat
xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation
vendor_redhat·2019-12-06·CVSS 6.8
CVE-2019-19579 [MEDIUM] CWE-266 xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation
xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in
Debian
CVE-2019-19579: xen - An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS...
vendor_debian·2019·CVSS 6.8
CVE-2019-19579 [MEDIUM] CVE-2019-19579: xen - An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS...
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device ca
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19579 xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation [fedora-all]
bugzilla·2019-12-06·CVSS 6.8
CVE-2019-19579 [MEDIUM] CVE-2019-19579 xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation [fedora-all]
CVE-2019-19579 xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg com
Bugzilla
CVE-2019-19579 xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation
bugzilla·2019-12-06·CVSS 6.8
CVE-2019-19579 [MEDIUM] CVE-2019-19579 xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation
CVE-2019-19579 xen: an untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation
XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. However this is not a strictly required step. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment. Hosts where these methods are used will still leave the system in a vulnerable state after the device comes back from a guest.
Upstream Reference:
http://xenbits.xen.org/xsa/advisory-306.html
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1780559]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
htt
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00011.htmlhttp://www.openwall.com/lists/oss-security/2019/12/05/7http://xenbits.xen.org/xsa/advisory-306.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJYT5FNGM7JSVHHW6B22TSAATBOAPFPD/https://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://www.openwall.com/lists/oss-security/2019/11/26/2https://xenbits.xen.org/xsa/advisory-306.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00011.htmlhttp://www.openwall.com/lists/oss-security/2019/12/05/7http://xenbits.xen.org/xsa/advisory-306.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJYT5FNGM7JSVHHW6B22TSAATBOAPFPD/https://seclists.org/bugtraq/2020/Jan/21https://www.debian.org/security/2020/dsa-4602https://www.openwall.com/lists/oss-security/2019/11/26/2https://xenbits.xen.org/xsa/advisory-306.html
2019-12-04
Published