CVE-2018-10981: Medium severity debian linux vulnerability
Published May 10, 2018
·Updated
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.
Affected Software
5 affected componentsFixes available
debian/xen
4.11.4+107-gef32c7afa2-14.14.6-14.14.5+94-ge49571868d-14.17.2+76-ge1f9cb16e2-1~deb12u14.17.2+76-ge1f9cb16e2-1
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
XEN Xen<=4.10.1
Remediation
Patch Available
Patch Available
Event History
May 10, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10981?
CVE-2018-10981 is rated as a denial of service vulnerability that can cause an infinite loop in the host OS.
2
How do I fix CVE-2018-10981?
To fix CVE-2018-10981, upgrade to a version of Xen that is 4.11.4+107-gef32c7afa2-1 or higher for the affected distributions.
3
Which versions of Xen are affected by CVE-2018-10981?
CVE-2018-10981 affects Xen versions up to and including 4.10.1.
4
What impact does CVE-2018-10981 have on x86 HVM guest OS users?
The impact of CVE-2018-10981 allows x86 HVM guest OS users to trigger a denial of service on the host OS.
5
Are there specific Debian versions impacted by CVE-2018-10981?
Yes, Debian versions 7.0, 8.0, and 9.0 are impacted by CVE-2018-10981.