Vulnerability Description
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exception handlers. When an exception occurs on an ARM system which is handled without changing processor level, some interrupts are unconditionally enabled during exception entry. So exceptions which occur when interrupts are masked will effectively unmask the interrupts. A malicious guest might contrive to arrange for critical Xen code to run with interrupts erroneously enabled. This could lead to data corruption, denial of service, or possibly even privilege escalation. However a precise attack technique has not been identified.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | <= 4.12.1 |
| Debian | Debian Linux | 9.0 |
| Fedoraproject | Fedora | 29 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2019/10/31/5Mailing ListPatchThird Party Advisory
- http://xenbits.xen.org/xsa/advisory-303.htmlPatchVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://seclists.org/bugtraq/2020/Jan/21Mailing ListThird Party Advisory
- https://www.debian.org/security/2020/dsa-4602Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/10/31/5Mailing ListPatchThird Party Advisory
- http://xenbits.xen.org/xsa/advisory-303.htmlPatchVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://seclists.org/bugtraq/2020/Jan/21Mailing ListThird Party Advisory
- https://www.debian.org/security/2020/dsa-4602Third Party Advisory
FAQ
What is CVE-2019-18422?
CVE-2019-18422 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are uncondition...
How severe is CVE-2019-18422?
CVE-2019-18422 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18422?
Check the references section above for vendor advisories and patch information. Affected products include: Xen Xen, Debian Debian Linux, Fedoraproject Fedora.