First published: Sat Dec 08 2018(Updated: )
An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | =4.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19963 has a high severity due to its potential for denial of service and privilege escalation on the host OS.
To fix CVE-2018-19963, upgrade to Xen version 4.11.1 or later where the vulnerability has been addressed.
CVE-2018-19963 affects users of Xen 4.11.0 running HVM guest operating systems.
CVE-2018-19963 enables HVM guest OS users to potentially crash the host OS or escalate their privileges.
Yes, CVE-2018-19963 is related to mishandling of x86 IOREQ server resource accounting for external emulators.