6.9
CVSSv2

CVE-2018-19962

Published: 08/12/2018 Updated: 07/11/2023
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.8 | Impact Score: 6 | Exploitability Score: 1.1
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in Xen up to and including 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen

debian debian linux 9.0

citrix xenserver 7.0

citrix xenserver 7.5

citrix xenserver 7.6

citrix xenserver 7.1

Vendor Advisories

An issue was discovered in Xen through 411x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones ...
Description of Problem A number of security vulnerabilities have been identified in Citrix XenServer that have deployment-dependent impacts These issues affect the following supported versions of Citrix XenServer: Citrix XenServer 76 Citrix XenServer 75 Citrix XenServer 71 LTSR CU1 Citrix XenServer 70 The following issues have been addressed: ...