Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10471

Опубликовано: 25 апр. 2018
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.

An OOB write issue was found in the way Xen hypervisor handled error in the Page Table Isolation (PTI) implementation, used to fix the Meltdown issue. It could occur while processing interrupt 'INT 0x80', when PV guest's vCPU has no handler for it. A malicious guest user/process could use this flaw to crash the hypervisor resulting in denial of service issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xenNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1566220xen: x86 PV guest may crash Xen with XPTI

EPSS

Процентиль: 36%
0.00425
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.

CVSS3: 6.5
nvd
больше 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.

CVSS3: 6.5
debian
больше 8 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS ...

CVSS3: 6.5
github
больше 4 лет назад

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.

suse-cvrf
больше 8 лет назад

Security update for xen

EPSS

Процентиль: 36%
0.00425
Низкий

5.6 Medium

CVSS3