[FEDORA-2019-6aad703290] Fedora 31: xen

Severity Critical
Affected Packages 1
CVEs 15

denial of service in find_next_bit() XSA-307, CVE-2019-19581, CVE-2019-19582 denial of service in HVM/PVH guest userspace code XSA-308,
CVE-2019-19583
privilege escalation due to malicious PV guest
XSA-309, CVE-2019-19578 Further issues with restartable PV type
change operations XSA-310, CVE-2019-19580 vulnerability in dynamic
height handling for AMD IOMMU pagetables XSA-311, CVE-2019-19577

Package Affected Version
pkg:rpm/fedora/xen?distro=fedora-31 < 4.12.1.8.fc31
ID
FEDORA-2019-6aad703290
Severity
critical
Severity from
CVE-2019-18425
URL
https://bodhi.fedoraproject.org/updates/FEDORA-2019-6aad703290
Published
2019-12-18T01:56:47
(4 years ago)
Modified
2019-12-18T01:56:47
(4 years ago)
Rights
Copyright 2019 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 1778185 Bug #1778185 - CVE-2019-19580 xen: Further issues with restartable PV type change operations (XSA-310) https://bugzilla.redhat.com/show_bug.cgi?id=1778185
Bugzilla 1778171 Bug #1778171 - CVE-2019-19583 xen: denial of service in HVM/PVH guest userspace code (XSA-308) https://bugzilla.redhat.com/show_bug.cgi?id=1778171
Bugzilla 1778161 Bug #1778161 - CVE-2019-19578 xen: privilege escalation due to malicious PV guest (XSA-309) https://bugzilla.redhat.com/show_bug.cgi?id=1778161
Bugzilla 1778194 Bug #1778194 - CVE-2019-19577 xen: vulnerability in dynamic height handling for AMD IOMMU pagetables (XSA-311 v2) https://bugzilla.redhat.com/show_bug.cgi?id=1778194
Bugzilla 1778191 Bug #1778191 - CVE-2019-19582 xen: denial of service in find_next_bit() (XSA-307) https://bugzilla.redhat.com/show_bug.cgi?id=1778191
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/xen?distro=fedora-31 fedora xen < 4.12.1.8.fc31 fedora-31
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...