CVE-2018-19962

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
08/12/2018
Last modified:
07/11/2023

Description

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* 4.11.1 (including)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:citrix:xenserver:7.0:*:*:*:*:*:*:*
cpe:2.3:a:citrix:xenserver:7.1:cu1:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:xenserver:7.5:*:*:*:*:*:*:*
cpe:2.3:a:citrix:xenserver:7.6:*:*:*:*:*:*:*