CVE-2018-19962
HIGH7.8EPSS 0.18%Published: 12/8/2018Modified: 12/3/2025
Also known as:ALPINE-CVE-2018-19962DEBIAN-CVE-2018-19962
Description
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.
Affected packages (2)
- Alpine/xenfrom 0, < 4.11.1-r0
- Debian/xenfrom 0, < 4.11.1-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |