CVE-2019-17350: Medium severity xen xapi vulnerability
Published Oct 8, 2019
·Updated
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchange operation.
Affected Software
4 affected componentsFixes available
debian/xen
4.11.4+107-gef32c7afa2-14.14.6-14.14.5+94-ge49571868d-14.17.2+76-ge1f9cb16e2-1~deb12u14.17.2+76-ge1f9cb16e2-1
XEN Xen<=4.12.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Oct 8, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17350?
The severity of CVE-2019-17350 is considered to be medium as it allows for a denial of service condition.
2
How do I fix CVE-2019-17350?
To fix CVE-2019-17350, update to a Xen version greater than 4.12.1.
3
Which versions of Xen are affected by CVE-2019-17350?
Xen versions up to and including 4.12.1 are affected by CVE-2019-17350.
4
What kind of attack does CVE-2019-17350 facilitate?
CVE-2019-17350 facilitates denial of service attacks through an infinite loop in compare-and-exchange operations.
5
Is Debian affected by CVE-2019-17350?
Yes, specific versions of Debian, particularly those using Xen versions up to 4.12.1, are affected by CVE-2019-17350.