Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19962

Опубликовано: 20 нояб. 2018
Источник: redhat
CVSS3: 8.1

Описание

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernel-xenWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-212
https://bugzilla.redhat.com/show_bug.cgi?id=1647573xen: insufficient TLB flushing / improper large page mappings with AMD IOMMUs

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVSS3: 7.8
nvd
около 7 лет назад

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVSS3: 7.8
debian
около 7 лет назад

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, po ...

CVSS3: 7.8
github
больше 3 лет назад

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVSS3: 7.8
fstec
около 7 лет назад

Уязвимость гипервизора Xen, связанная с небезопасным объединением небольших IOMMU с более крупными, позволяющая нарушителю повысить свои привилегии

8.1 High

CVSS3