First published: Thu Nov 01 2018(Updated: )
An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is not properly restricted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | >=4.9.0<=4.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18883 has a high severity level due to its potential to cause a denial of service on the host operating system.
CVE-2018-18883 exploits nested VT-x by not properly restricting access, allowing HVM and PVH guests to dereference a null pointer.
CVE-2018-18883 affects Xen versions 4.9.x through 4.11.x on Intel x86 platforms.
The potential impacts of CVE-2018-18883 include denial of service on the host OS and possibly other unspecified impacts.
To mitigate CVE-2018-18883, it is recommended to upgrade your Xen installation to a version that is not vulnerable.