XEN CVE-2018-15471 Out of Bounds Memory Access Vulnerability
BID:106791
Info
XEN CVE-2018-15471 Out of Bounds Memory Access Vulnerability
| Bugtraq ID: | 106791 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-15471 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 14 2018 12:00AM |
| Updated: | Aug 14 2018 12:00AM |
| Credit: | Felix Wilhelm from Google Project Zero. |
| Vulnerable: |
Xen Xen 0 Linux kernel 4.19.13 Linux kernel 4.19.6 Linux kernel 4.19.3 Linux kernel 4.19.2 Linux kernel 4.18.16 Linux kernel 4.18.12 Linux kernel 4.18.11 Linux kernel 4.18.9 Linux kernel 4.18.6 Linux kernel 4.18.5 Linux kernel 4.17.7 Linux kernel 4.17.3 Linux kernel 4.17.2 Linux kernel 4.17.1 Linux kernel 4.16.11 Linux kernel 4.16.9 Linux kernel 4.16.6 Linux kernel 4.16.3 Linux kernel 4.15.14 Linux kernel 4.15.11 Linux kernel 4.15.9 Linux kernel 4.15.4 Linux kernel 4.14.78 Linux kernel 4.14.71 Linux kernel 4.14.67 Linux kernel 4.14.31 Linux kernel 4.14.13 Linux kernel 4.14.11 Linux kernel 4.14.10 Linux kernel 4.14.6 Linux kernel 4.14.5 Linux kernel 4.14.1 Linux kernel 4.13.11 Linux kernel 4.13.10 Linux kernel 4.13.9 Linux kernel 4.13.8 Linux kernel 4.13.7 Linux kernel 4.13.6 Linux kernel 4.13.4 Linux kernel 4.13.3 Linux kernel 4.12.9 Linux kernel 4.12.4 Linux kernel 4.12.3 Linux kernel 4.12.2 Linux kernel 4.11.9 Linux kernel 4.11.5 Linux kernel 4.11.4 Linux kernel 4.11.3 Linux kernel 4.11.2 Linux kernel 4.11.1 Linux kernel 4.11 Linux kernel 4.10.15 Linux kernel 4.10.13 Linux kernel 4.10.12 Linux kernel 4.10.10 Linux kernel 4.10.6 Linux kernel 4.10.4 Linux kernel 4.10 Linux kernel 4.9.135 Linux kernel 4.9.128 Linux kernel 4.9.91 Linux kernel 4.9.74 Linux kernel 4.9.71 Linux kernel 4.9.68 Linux kernel 4.9.36 Linux kernel 4.9.13 Linux kernel 4.9.8 Linux kernel 4.9.4 Linux kernel 4.9.3 Linux kernel 4.8.11 Linux kernel 4.7.4 Linux kernel 4.9.9 Linux kernel 4.9.11 Linux kernel 4.9 Linux kernel 4.8.7 Linux kernel 4.8.6 Linux kernel 4.8.3 Linux kernel 4.8.14 Linux kernel 4.8.13 Linux kernel 4.8.12 Linux kernel 4.8.1 Linux kernel 4.8 Linux kernel 4.7.9 Linux kernel 4.7-rc6 Linux kernel 4.7-rc5 Linux kernel 4.7-rc1 Linux kernel 4.19 Linux kernel 4.18.1 Linux kernel 4.18-rc5 Linux kernel 4.18 Linux kernel 4.17.4 Linux kernel 4.17.11 Linux kernel 4.17.10 Linux kernel 4.17-rc2 Linux kernel 4.17 Linux kernel 4.16-rc7 Linux kernel 4.16-rc6 Linux kernel 4.16-rc Linux kernel 4.16 Linux kernel 4.15.8 Linux kernel 4.15.7 Linux kernel 4.15.16 Linux kernel 4.15-rc8 Linux kernel 4.15-rc5 Linux kernel 4.15-rc4 Linux kernel 4.15 Linux kernel 4.14.8 Linux kernel 4.14.7 Linux kernel 4.14.4 Linux kernel 4.14.3 Linux kernel 4.14.2 Linux kernel 4.14.15 Linux kernel 4.14.14 Linux kernel 4.14.0-rc1 Linux kernel 4.14-rc5 Linux kernel 4.14-rc1 Linux kernel 4.14 Linux kernel 4.13.5 Linux kernel 4.13.2 Linux kernel 4.13.1 Linux kernel 4.13-rc4 Linux kernel 4.13-rc1 Linux kernel 4.13 Linux kernel 4.12.10 Linux kernel 4.12.1 Linux kernel 4.12-rc1 Linux kernel 4.12 Linux kernel 4.11.8 Linux kernel 4.11.7 Linux kernel 4.11-rc8 Linux kernel 4.11-rc7 Linux kernel 4.11-rc6 Linux kernel 4.11-rc5 Linux kernel 4.11-rc4 Linux kernel 4.11-rc3 Linux kernel 4.11-rc2 Linux kernel 4.11-rc1 Linux kernel 4.11 Linux kernel 4.10.9 Linux kernel 4.10.8 Linux kernel 4.10.7 Linux kernel 4.10.5 Linux kernel 4.10.3 Linux kernel 4.10.2 Linux kernel 4.10.11 Linux kernel 4.10.1 Linux kernel 4.10-rc8 Linux kernel 4.10-rc1 |
| Not Vulnerable: | |
Discussion
XEN CVE-2018-15471 Out of Bounds Memory Access Vulnerability
XEN is prone to an out-of-bounds memory access vulnerability.
Successful exploits may allow an attacker to cause out-of-bounds memory access condition and obtain sensitive information, gain elevated privileges or to cause denial-of-service condition that may lead to further attacks.
Linux kernel version 4.7 and above are vulnerable.
XEN is prone to an out-of-bounds memory access vulnerability.
Successful exploits may allow an attacker to cause out-of-bounds memory access condition and obtain sensitive information, gain elevated privileges or to cause denial-of-service condition that may lead to further attacks.
Linux kernel version 4.7 and above are vulnerable.
Exploit / POC
XEN CVE-2018-15471 Out of Bounds Memory Access Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
XEN CVE-2018-15471 Out of Bounds Memory Access Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.