Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2018-15468
HistoryAug 17, 2018 - 6:29 p.m.

CVE-2018-15468

2018-08-1718:29:00
Debian Security Bug Tracker
security-tracker.debian.org
17

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

EPSS

0

Percentile

12.6%

An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do not. In particular, Branch Trace Store is not virtualised by the processor, and software has to be careful to configure it suitably not to lock up the core. As a result, it must only be available to fully trusted guests. Unfortunately, in the case that vPMU is disabled, all value checking was skipped, allowing the guest to choose any MSR_DEBUGCTL setting it likes. A malicious or buggy guest administrator (on Intel x86 HVM or PVH) can lock up the entire host, causing a Denial of Service.

OSVersionArchitecturePackageVersionFilename
Debian12allxen< 4.11.1~pre.20180911.5acdd26fdc+dfsg-2xen_4.11.1~pre.20180911.5acdd26fdc+dfsg-2_all.deb
Debian11allxen< 4.11.1~pre.20180911.5acdd26fdc+dfsg-2xen_4.11.1~pre.20180911.5acdd26fdc+dfsg-2_all.deb
Debian999allxen< 4.11.1~pre.20180911.5acdd26fdc+dfsg-2xen_4.11.1~pre.20180911.5acdd26fdc+dfsg-2_all.deb
Debian13allxen< 4.11.1~pre.20180911.5acdd26fdc+dfsg-2xen_4.11.1~pre.20180911.5acdd26fdc+dfsg-2_all.deb

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS3

6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

EPSS

0

Percentile

12.6%