CVE-2018-19963

Published: 08 December 2018

An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled.

Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
xen
Launchpad, Ubuntu, Debian
Upstream
Released (4.11.1-1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(code not present)
Ubuntu 16.04 LTS (Xenial Xerus) Not vulnerable
(code not present)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was needs-triage)
Binaries built from this source package are in Universe and so are supported by the community.