CVE-2018-15468
xen - security update
6.0
MEDIUM
CVSS 3.1
EPSS 0.34%
描述
An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do not. In particular, Branch Trace Store is not virtualised by the processor, and software has to be careful to configure it suitably not to lock up the core. As a result, it must only be available to fully trusted guests. Unfortunately, in the case that vPMU is disabled, all value checking was skipped, allowing the guest to choose any MSR_DEBUGCTL setting it likes. A malicious or buggy guest administrator (on Intel x86 HVM or PVH) can lock up the entire host, causing a Denial of Service.
如何修補 CVE-2018-15468
要修補 CVE-2018-15468,請將受影響套件升級到下列已修補版本。
- —升級至 4.11.1-r0 或更新版本
- —升級至 4.11.1~pre.20180911.5acdd26fdc+dfsg-2 或更新版本
- —升級至 4.8.4+xsa273+shim4.10.1+xsa273-1+deb9u10 或更新版本
CVE-2018-15468 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 4.11.1-r0
- from 0, < 4.11.1~pre.20180911.5acdd26fdc+dfsg-2
- from 0, < 4.8.4+xsa273+shim4.10.1+xsa273-1+deb9u10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.0 | CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H |