An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) if shadow mode and log-dirty mode are in place, because of an incorrect assertion related to M2P.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1040771 | vdb entry |
https://xenbits.xen.org/xsa/advisory-251.html | patch vendor advisory mitigation |
https://lists.debian.org/debian-lts-announce/2018/01/msg00003.html | mailing list |
http://www.openwall.com/lists/oss-security/2017/12/12/5 | mailing list |
https://lists.debian.org/debian-lts-announce/2018/10/msg00009.html | mailing list |
https://security.gentoo.org/glsa/201801-14 | vendor advisory |
http://www.securityfocus.com/bid/102175 | vdb entry |
https://www.debian.org/security/2018/dsa-4112 | vendor advisory |
https://support.citrix.com/article/CTX232096 |