CVE-2018-12891 is a Denial of Service (DoS) vulnerability affecting Xen versions 3.4 through 4.10.x on x86 systems, specifically impacting multi-vCPU PV guests. A malicious or buggy guest can exploit certain PV MMU operations that bypass preemption checks, leading to an indeterminate blocking of a physical CPU. This vulnerability has a CVSS score of 6.5 (Medium) due to its local attack vector and high impact on availability, allowing a low-privileged attacker to cause a host-wide DoS. There is no known exploit code available, and the vulnerability has received minimal community discussion or media coverage, indicating it is not currently being actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
<= 4.10.1CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.