---
title: "CVE-2018-12892\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-12892?format=md
keywords: index, follow
---

# CVE-2018-12892

Publication date 2 July 2018

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**9.9 · Critical**

[Score breakdown](https://ubuntu.com/security/CVE-2018-12892?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the
readonly flag to qemu when setting up a SCSI disk, due to what was probably
an erroneous merge conflict resolution. Malicious guest administrators or
(in some situations) users may be able to write to supposedly read-only
disk images. Only emulated SCSI disks (specified as "sd" in the libxl disk
configuration, or an equivalent) are affected. IDE disks ("hd") are not
affected (because attempts to make them readonly are rejected).
Additionally, CDROM devices (that is, devices specified to be presented to
the guest as CDROMs, regardless of the nature of the backing storage on the
host) are not affected; they are always read only. Only systems using
qemu-xen (rather than qemu-xen-traditional) as the device model version are
vulnerable. Only systems using libxl or libxl-based toolstacks are
vulnerable. (This includes xl, and libvirt with the libxl driver.) The
vulnerability is present in Xen versions 4.7 and later. (In earlier
versions, provided that the patch for XSA-142 has been applied, attempts to
create read only disks are rejected.) If the host and guest together
usually support PVHVM, the issue is exploitable only if the malicious guest
administrator has control of the guest kernel or guest kernel command line.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2018-12892?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| xen | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.10 cosmic | Ignored end of life |
| 18.04 LTS bionic | Vulnerable |
| 17.10 artful | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

hypervisor packages are in universe. For
issues in the hypervisor, add appropriate
tags to each section, ex:
Tags\_xen: universe-binary

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

9.9 · Critical

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Changed |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 9.9 · Critical |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12892)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-12892)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-12892)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-12892)

### Other references

* <https://xenbits.xen.org/xsa/advisory-266.html>
* <https://www.cve.org/CVERecord?id=CVE-2018-12892>
