CVE-2018-7540: Medium severity XEN Xen vulnerability
Published Feb 27, 2018
·Updated
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L4 pagetable freeing.
Affected Software
3 affected componentsFixes available
debian/xen
4.11.4+107-gef32c7afa2-14.14.6-14.14.5+94-ge49571868d-14.17.1+2-gb773c48e36-14.17.2+55-g0b56bed864-1
XEN Xen<=4.10.0
Debian Debian Linux=9.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xento a version that resolves this vulnerability.Fixed in 4.11.4+107-gef32c7afa2-1Fixed in 4.14.6-1Fixed in 4.14.5+94-ge49571868d-1Fixed in 4.17.1+2-gb773c48e36-1Fixed in 4.17.2+55-g0b56bed864-1
Event History
Feb 27, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7540?
CVE-2018-7540 is classified as a denial of service vulnerability affecting Xen.
2
How do I fix CVE-2018-7540?
To mitigate CVE-2018-7540, upgrade to Xen versions 4.11.4+107-gef32c7afa2-1 or later.
3
What systems are affected by CVE-2018-7540?
CVE-2018-7540 affects Xen versions up to 4.10.x and Debian Linux 9.0.
4
What type of attack does CVE-2018-7540 facilitate?
CVE-2018-7540 allows an x86 PV guest OS user to induce a host OS CPU hang.
5
Which platforms are impacted by CVE-2018-7540?
CVE-2018-7540 impacts platforms using Xen hypervisor, specifically in virtualized environments.