CVE-2019-17349: Medium severity xen xapi vulnerability
Published Oct 8, 2019
·Updated
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreExcl operation.
Affected Software
4 affected componentsFixes available
debian/xen
4.11.4+107-gef32c7afa2-14.14.6-14.14.5+94-ge49571868d-14.17.2+76-ge1f9cb16e2-1~deb12u14.17.2+76-ge1f9cb16e2-1
XEN Xen<=4.12.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Oct 8, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17349?
CVE-2019-17349 is classified as a denial of service vulnerability that can lead to an infinite loop.
2
How do I fix CVE-2019-17349?
To fix CVE-2019-17349, upgrade to Xen versions 4.12.2 or later, or apply the relevant patches provided by your Linux distribution.
3
What systems are affected by CVE-2019-17349?
CVE-2019-17349 affects Xen versions up to 4.12.1 and certain Debian Linux versions including 9.0 and 10.0.
4
Can CVE-2019-17349 be exploited remotely?
CVE-2019-17349 can potentially be exploited by Arm domU attackers on the same host.
5
Is there a public patch for CVE-2019-17349?
Yes, patches for CVE-2019-17349 are available from the Xen project and relevant Linux distributions.