| CVE-ID |
CVE-2018-12892
|
• CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
|
| Description |
| An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass
the readonly flag to qemu when setting up a SCSI disk, due to what was
probably an erroneous merge conflict resolution. Malicious guest
administrators or (in some situations) users may be able to write to
supposedly read-only disk images. Only emulated SCSI disks (specified
as "sd" in the libxl disk configuration, or an equivalent) are
affected. IDE disks ("hd") are not affected (because attempts to make
them readonly are rejected). Additionally, CDROM devices (that is,
devices specified to be presented to the guest as CDROMs, regardless
of the nature of the backing storage on the host) are not affected;
they are always read only. Only systems using qemu-xen (rather than
qemu-xen-traditional) as the device model version are vulnerable. Only
systems using libxl or libxl-based toolstacks are vulnerable. (This
includes xl, and libvirt with the libxl driver.) The vulnerability is
present in Xen versions 4.7 and later. (In earlier versions, provided
that the patch for XSA-142 has been applied, attempts to create read
only disks are rejected.) If the host and guest together usually
support PVHVM, the issue is exploitable only if the malicious guest
administrator has control of the guest kernel or guest kernel command
line.
|
| References |
|
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
|
|
|
| Assigning CNA |
| MITRE Corporation |
| Date Entry Created |
| 20180626 |
Disclaimer: The entry creation date may reflect when
the CVE ID was allocated or reserved, and does not
necessarily indicate when this vulnerability was
discovered, shared with the affected vendor, publicly
disclosed, or updated in CVE.
|
| Phase (Legacy) |
| Assigned (20180626) |
| Votes (Legacy) |
|
| Comments (Legacy) |
|
| Proposed (Legacy) |
| N/A |
|
This is an entry on the CVE List, which provides common identifiers for publicly known cybersecurity vulnerabilities. |
|
|
|
For More Information: cve@mitre.org
|