CVE-2019-17351: Medium severity XEN Xen vulnerability
An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef36ab967c7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1 - Upgrade
Upgrade
Linux kernel (drivers/xen/balloon.c)to a version that resolves this vulnerability.Fixed in 5.2.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CID-6ef36ab967c7
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17351?
CVE-2019-17351 is classified as a medium severity vulnerability due to its potential for denial of service.
How do I fix CVE-2019-17351?
To fix CVE-2019-17351, update the Linux kernel to version 5.2.3 or later, or Xen versions up to 4.12.1.
What systems are affected by CVE-2019-17351?
CVE-2019-17351 affects Linux kernel versions before 5.2.3 and Xen versions up to 4.12.x.
What type of vulnerability is CVE-2019-17351?
CVE-2019-17351 is a resource consumption vulnerability that can lead to a denial of service.
Who can exploit CVE-2019-17351?
CVE-2019-17351 can be exploited by guest OS users to consume excessive resources.