First published: Tue Oct 08 2019(Updated: )
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen Xen | >=4.1.0<=4.11.2 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
debian/xen | 4.11.4+107-gef32c7afa2-1 4.14.6-1 4.14.5+94-ge49571868d-1 4.17.2+76-ge1f9cb16e2-1~deb12u1 4.17.2+76-ge1f9cb16e2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17347 is a vulnerability in Xen that allows x86 PV guest OS users to cause a denial of service or gain privileges by manipulating the virtualized %cr4 register.
The severity of CVE-2019-17347 is not specified in the provided information. Please refer to the references for more details.
To fix CVE-2019-17347, update Xen to version 4.11.4+107-gef32c7afa2-1, 4.14.5+94-ge49571868d-1, 4.17.1+2-gb773c48e36-1, or 4.17.2-1.
Xen versions up to 4.11.x are affected by CVE-2019-17347.
More information about CVE-2019-17347 can be found on the Xen advisory page and the Debian security tracker.