An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and host OS hang) by leveraging the mishandling of Populate on Demand (PoD) errors.
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
Link | Tags |
---|---|
https://lists.debian.org/debian-lts-announce/2018/10/msg00021.html | mailing list |
http://www.securityfocus.com/bid/102129 | vdb entry third party advisory |
https://xenbits.xen.org/xsa/advisory-246.html | issue tracking patch mitigation vendor advisory |
https://lists.debian.org/debian-lts-announce/2018/01/msg00003.html | mailing list |
http://www.securityfocus.com/bid/102008 | vdb entry third party advisory |
http://www.securitytracker.com/id/1039878 | vdb entry third party advisory |
https://security.gentoo.org/glsa/201801-14 | vendor advisory |
http://www.securityfocus.com/bid/105954 | vdb entry |
https://support.citrix.com/article/CTX230138 | issue tracking third party advisory |