Vulnerability Name:

CVE-2018-5244 (CCN-137096)

Assigned:2018-01-04
Published:2018-01-04
Updated:2018-10-31
Summary:In Xen 4.10, new infrastructure was introduced as part of an overhaul to how MSR emulation happens for guests. Unfortunately, one tracking structure isn't freed when a vcpu is destroyed. This allows guest OS administrators to cause a denial of service (host OS memory consumption) by rebooting many times.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-5244

Source: BID
Type: Third Party Advisory, VDB Entry
102433

Source: CCN
Type: BID-102433
Xen CVE-2018-5244 Memory Corruption Vulnerability

Source: SECTRACK
Type: UNKNOWN
1040774

Source: CCN
Type: Xen Security Advisory XSA-253
x86: memory leak with MSR emulation

Source: XF
Type: UNKNOWN
xen-msr-emulation-dos(137096)

Source: GENTOO
Type: UNKNOWN
GLSA-201810-06

Source: CONFIRM
Type: Issue Tracking, Mitigation, Vendor Advisory
https://xenbits.xen.org/xsa/advisory-253.html

Vulnerable Configuration:Configuration 1:
  • cpe:/o:xen:xen:*:*:*:*:*:*:*:* (Version >= 4.10.0

  • Configuration CCN 1:
  • cpe:/a:xensource:xen:4.10:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20185244
    V
    CVE-2018-5244
    2023-06-22
    oval:org.opensuse.security:def:7831
    P
    xen-libs-4.17.0_06-150500.1.10 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:635
    P
    Security update for rubygem-activesupport-5_1 (Moderate) (in QA)
    2022-09-29
    oval:org.opensuse.security:def:589
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:94253
    P
    (Important)
    2022-07-06
    oval:org.opensuse.security:def:3225
    P
    libopus0-1.1-3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3535
    P
    java-1_8_0-openjdk-1.8.0.222-27.35.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94855
    P
    xen-libs-4.16.0_08-150400.2.12 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95165
    P
    xen-4.16.0_08-150400.2.12 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:917
    P
    Security update for vim (Important)
    2022-06-16
    oval:org.opensuse.security:def:1079
    P
    Security update for fwupd (Important) (in QA)
    2022-06-13
    oval:org.opensuse.security:def:293
    P
    python3-targetcli-fb-2.1.53-1.12 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:336
    P
    xen-libs-4.14.1_16-1.6 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:388
    P
    xen-libs-4.16.0_08-150400.2.12 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:1666
    P
    Security update for libvirt (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:1601
    P
    Security update for the Linux Kernel (Important)
    2022-03-09
    oval:org.opensuse.security:def:113591
    P
    xen-4.15.1_01-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:68101
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP1) (Important)
    2021-12-14
    oval:org.opensuse.security:def:100686
    P
    (Moderate)
    2021-12-03
    oval:org.opensuse.security:def:106977
    P
    xen-4.15.1_01-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71419
    P
    xen-libs-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89833
    P
    xen-libs-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61678
    P
    xen-libs-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103488
    P
    xen-libs-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96798
    P
    xen-libs-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63246
    P
    xen-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:90081
    P
    xen-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103736
    P
    xen-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:97046
    P
    xen-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71189
    P
    ghostscript-9.26a-3.15.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71341
    P
    libzip-devel-1.5.1-1.9 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2157
    P
    xen-4.12.0_12-1.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:1265
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP3) (Important)
    2021-09-16
    oval:org.opensuse.security:def:66922
    P
    Security update for openssl-1_0_0 (Low)
    2021-09-09
    oval:org.opensuse.security:def:93973
    P
    (Important)
    2021-09-03
    oval:org.opensuse.security:def:64754
    P
    Security update for qemu (Moderate)
    2021-08-27
    oval:org.opensuse.security:def:70278
    P
    Security update for php7 (Important)
    2021-08-20
    oval:org.opensuse.security:def:69904
    P
    Security update for c-ares (Important)
    2021-08-17
    oval:org.opensuse.security:def:46950
    P
    git-core-1.8.5.6-18.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47940
    P
    PackageKit-1.1.3-24.9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47111
    P
    openssh-7.2p2-55.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48109
    P
    libexif12-0.6.21-8.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48245
    P
    nmap-6.46-3.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48061
    P
    lcms2-2.7-9.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47143
    P
    radvd-1.9.7-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47971
    P
    cifs-utils-6.9-9.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47125
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48171
    P
    libplist3-1.12-20.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47544
    P
    MozillaFirefox-52.9.0esr-109.38.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48153
    P
    libmysqlclient18-10.0.40.1-2.9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47275
    P
    grub2-2.02-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48042
    P
    hplip-3.16.11-1.33 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47246
    P
    e2fsprogs-1.42.11-15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48236
    P
    logwatch-7.4.3-15.65 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47545
    P
    SuSEfirewall2-3.6.312.333-3.13.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48301
    P
    rzsz-0.12.21~rc-1001.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47367
    P
    libksba8-1.3.0-23.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47439
    P
    libzip2-0.11.1-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48267
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47559
    P
    audiofile-0.3.6-10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47600
    P
    e2fsprogs-1.43.8-1.19 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47515
    P
    tftp-5.2-10.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47571
    P
    ceph-common-12.2.8+git.1536505967.080f2248ff-2.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48338
    P
    wget-1.14-21.10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47680
    P
    libXp6-1.0.2-3.57 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47601
    P
    ecryptfs-utils-103-8.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47729
    P
    libjson-c2-0.11-2.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47663
    P
    libHX28-3.18-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47873
    P
    qemu-2.11.2-4.14 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47615
    P
    gdk-pixbuf-lang-2.34.0-19.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47813
    P
    libxerces-c-3_1-3.1.1-12.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47811
    P
    libwireshark9-2.4.9-48.29.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48005
    P
    fetchmail-6.3.26-12.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47736
    P
    liblouis-data-2.6.4-6.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47875
    P
    res-signingkeys-3.0.38-52.26.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47110
    P
    openslp-2.0.0-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48025
    P
    gnome-shell-search-provider-nautilus-3.20.3-23.12.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48097
    P
    libaudit1-2.8.1-10.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47929
    P
    xscreensaver-5.22-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:2296
    P
    xen-4.14.1_16-1.6 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:101411
    P
    xen-4.14.1_16-1.6 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63385
    P
    xen-4.14.1_16-1.6 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:1023
    P
    less-530-1.6 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100966
    P
    libqpdf26-9.0.2-1.36 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101112
    P
    xen-libs-4.14.1_16-1.6 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72095
    P
    xen-libs-4.14.1_16-1.6 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62354
    P
    xen-libs-4.14.1_16-1.6 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1545
    P
    Security update for the Linux Kernel (Important)
    2021-07-13
    oval:org.opensuse.security:def:68001
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (Important)
    2021-06-18
    oval:org.opensuse.security:def:66830
    P
    Security update for postgresql10 (Moderate)
    2021-06-14
    oval:org.opensuse.security:def:48828
    P
    dia-0.97.3-15.63 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48459
    P
    libMagickCore-6_Q16-1-6.8.8.1-33.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48543
    P
    libpython3_4m1_0-3.4.1-12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71076
    P
    postgresql-10-6.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48605
    P
    python-cupshelpers-1.5.7-7.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48515
    P
    liblcms1-1.19-17.28 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48670
    P
    flash-player-11.2.202.406-1.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48599
    P
    perl-XML-LibXML-2.0019-5.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46814
    P
    perl-Cyrus-IMAP-2.3.18-35.71 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48680
    P
    libIlmImf-Imf_2_1-21-32bit-2.1.0-4.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48701
    P
    pidgin-otr-4.0.0-6.18 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48734
    P
    libgio-fam-2.38.2-5.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48661
    P
    ImageMagick-6.8.8.1-5.21 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71123
    P
    xen-libs-4.10.1_04-1.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46815
    P
    perl-HTML-Parser-3.71-1.178 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48772
    P
    gcc48-gij-32bit-4.8.5-30.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48726
    P
    icu-52.1-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61382
    P
    xen-libs-4.10.1_04-1.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46829
    P
    python-pyOpenSSL-0.14-1.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48757
    P
    rhythmbox-3.0.2-1.92 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:73613
    P
    Security update for libxml2 (Moderate)
    2021-05-05
    oval:org.opensuse.security:def:64489
    P
    Security update for p7zip (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:70009
    P
    Security update for gnutls (Important)
    2021-03-24
    oval:org.opensuse.security:def:64667
    P
    Security update for python (Moderate)
    2021-03-11
    oval:org.opensuse.security:def:49304
    P
    Security update for python-Jinja2 (Important)
    2021-02-25
    oval:org.opensuse.security:def:70173
    P
    Security update for openssh (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:67736
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2020-12-08
    oval:org.opensuse.security:def:107632
    P
    xen-4.13.1_02-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2222
    P
    xen-4.13.1_02-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71747
    P
    xen-libs-4.13.1_02-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62006
    P
    xen-libs-4.13.1_02-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63311
    P
    xen-4.13.1_02-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2101
    P
    xen-4.10.1_04-1.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116910
    P
    xen-libs-4.13.1_02-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107352
    P
    xen-libs-4.13.1_02-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71454
    P
    ceph-common-15.2.2.18+g1dbcddb5d8-1.10 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117190
    P
    xen-4.13.1_02-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48976
    P
    bluez-cups-5.13-5.12.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49030
    P
    libpolkit0-32bit-0.113-5.18.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63190
    P
    xen-4.10.1_04-1.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:50053
    P
    davfs2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50107
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73344
    P
    xen-libs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73495
    P
    cups-ddk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49358
    P
    xen-libs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64402
    P
    libwavpack1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49932
    P
    clamsap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67836
    P
    xen-libs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49986
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49988
    P
    apache2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50042
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66561
    P
    libyaml-0-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73226
    P
    libssh2-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66653
    P
    xen-libs on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.artful:def:20185244000
    V
    CVE-2018-5244 on Ubuntu 17.10 (artful) - medium.
    2018-01-05
    oval:com.ubuntu.xenial:def:201852440000000
    V
    CVE-2018-5244 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-01-05
    oval:com.ubuntu.trusty:def:20185244000
    V
    CVE-2018-5244 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-01-05
    oval:com.ubuntu.xenial:def:20185244000
    V
    CVE-2018-5244 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-01-05
    BACK
    xen xen *
    xensource xen 4.10