5.6
CVSSv3

CVE-2018-19965

Published: 08/12/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.6 | Impact Score: 4 | Exploitability Score: 1.1
VMScore: 419
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

An issue exists in Xen up to and including 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen

citrix xenserver 7.0

citrix xenserver 7.5

citrix xenserver 7.6

citrix xenserver 7.1

debian debian linux 9.0

Vendor Advisories

An issue was discovered in Xen through 411x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation ...
Description of Problem A number of security vulnerabilities have been identified in Citrix XenServer that have deployment-dependent impacts These issues affect the following supported versions of Citrix XenServer: Citrix XenServer 76 Citrix XenServer 75 Citrix XenServer 71 LTSR CU1 Citrix XenServer 70 The following issues have been addressed: ...

Github Repositories

Architecture internals learning path from Open Security Training, provides a set of resources to complete the learning path, includes code-base, videos, techniques, useful articles and concepts to understand the courses.

πŸ”‘ Open Security Training Architecture Architecture internals learning path from Open Security Training, provides a set of resources to complete the learning path, includes code-base, videos, techniques, useful articles and concepts to understand the courses provided from Open Security Training Register in post2fyi Resources Videos: wwwyoutubecom/watch?v=eItru0

Architecture internals learning path from Open Security Training, provides a set of resources to complete the learning path, includes code-base, videos, techniques, useful articles and concepts to understand the courses.

πŸ”‘ Open Security Training Architecture Architecture internals learning path from Open Security Training, provides a set of resources to complete the learning path, includes code-base, videos, techniques, useful articles and concepts to understand the courses provided from Open Security Training Register in post2fyi Resources Videos: wwwyoutubecom/watch?v=eItru0