CVE-2018-19967 is a denial-of-service vulnerability affecting Xen through version 4.11.x on Intel x86 platforms, specifically impacting Debian and Xen installations. A malicious guest OS user can exploit this flaw to cause the host OS to hang due to Xen's failure to properly handle certain Intel HLE transactions. Rated as Medium severity with a CVSS score of 6.5, this local attack requires low privileges and complexity, leading to a high availability impact. There is currently no evidence of active exploitation, and no public exploit code or significant community discussion has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.11.1CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.