CVE-2019-17347: Input Validation
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-17347?
CVE-2019-17347 is a vulnerability in Xen that allows x86 PV guest OS users to cause a denial of service or gain privileges by manipulating the virtualized %cr4 register.
What is the severity of CVE-2019-17347?
The severity of CVE-2019-17347 is not specified in the provided information. Please refer to the references for more details.
How can I fix CVE-2019-17347?
To fix CVE-2019-17347, update Xen to version 4.11.4+107-gef32c7afa2-1, 4.14.5+94-ge49571868d-1, 4.17.1+2-gb773c48e36-1, or 4.17.2-1.
What software is affected by CVE-2019-17347?
Xen versions up to 4.11.x are affected by CVE-2019-17347.
Where can I find more information about CVE-2019-17347?
More information about CVE-2019-17347 can be found on the Xen advisory page and the Debian security tracker.