information about 10 vulnerabilities in the Xen hypervisor, of which five (, , , , ) potentially allow breaking out of the current guest environment and escalating privileges, one vulnerability (CVE-2019-17347) allows an unprivileged process to take control over processes of other users in the same guest system, the remaining four (CVE-2019-17344, CVE-2019-17345, CVE-2019-17348, CVE-2019-17351) vulnerabilities can lead to denial of service (crash of the host environment). Issues have been fixed in releases .
- — the ability for an attacker-controlled guest system to access the hypervisor level. The issue manifests only on x86 systems and can be executed from guest systems operating in paravirtualization (PV) mode when a new PCI device is passed through to a running guest system. The vulnerability does not manifest in guest systems operating in HVM and PVH modes;
- — memory leak that potentially allows privilege escalation or access to data from other guest systems.
The issue manifests only on hosts with more than 16 TB of RAM in 64-bit systems and 168 GB in 32-bit.
The vulnerability can only be exploited from guest systems in PV mode (it does not manifest in HVM and PVH modes when using libxl); - — a vulnerability when using PCID (Process Context Identifiers) to enhance performance against attack mitigation
Meltdown allows access to data from other guest systems and potentially escalates privileges. The vulnerability can only be exploited from guest systems in PV mode on x86 systems (the issue does not manifest in HVM and PVH modes, as well as in configurations that lack guest systems with PCID enabled (PCID is enabled by default)); - — an issue in the XENMEM_exchange hypercall implementation allows privilege escalation in environments with only one guest system. The vulnerability can only be exploited from guest systems in PV mode (it does not manifest in HVM and PVH modes);
- An incorrect mapping in IOMMU allows access from the guest system to the physical device, enabling DMA to alter its own memory page table and gain host-level access. The vulnerability only manifests in guest systems operating in PV mode with permission to passthrough PCI devices.
Source: opennet.ru
