CVE Database
/

CVE-2019-18425

Back to search

CVE-2019-18425

Published: Oct 31, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table accesses are performed by the emulating code. Such accesses should respect the guest specified limits, unless otherwise guaranteed to fail in such a case. Without this, emulation of 32-bit guest user mode calls through call gates would allow guest user mode to install and then use descriptors of their choice, as long as the guest kernel did not itself install an LDT. (Most OSes don't install any LDT by default). 32-bit PV guest user mode can elevate its privileges to that of the guest kernel. Xen versions from at least 3.2 onwards are affected. Only 32-bit PV guest user mode can leverage this vulnerability. HVM, PVH, as well as 64-bit PV guests cannot leverage this vulnerability. Arm systems are unaffected.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2019:2506
vendor-advisory
x_refsource_SUSE
FEDORA-2019-865bb16900
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-376ec5c107
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-cbb732f760
vendor-advisory
x_refsource_FEDORA
DSA-4602
vendor-advisory
x_refsource_DEBIAN
GLSA-202003-56
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now