| CVE-ID |
CVE-2018-15470
|
• CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
|
| Description |
| An issue was discovered in Xen through 4.11.x. The logic in oxenstored
for handling writes depended on the order of evaluation of expressions
making up a tuple. As indicated in section 7.7.3 "Operations on data
structures" of the OCaml manual, the order of evaluation of
subexpressions is not specified. In practice, different implementations
behave differently. Thus, oxenstored may not enforce the configured
quota-maxentity. This allows a malicious or buggy guest to write as
many xenstore entries as it wishes, causing unbounded memory usage in
oxenstored. This can lead to a system-wide DoS.
|
| References |
|
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
|
|
|
| Assigning CNA |
| MITRE Corporation |
| Date Entry Created |
| 20180817 |
Disclaimer: The entry creation date may reflect when
the CVE ID was allocated or reserved, and does not
necessarily indicate when this vulnerability was
discovered, shared with the affected vendor, publicly
disclosed, or updated in CVE.
|
| Phase (Legacy) |
| Assigned (20180817) |
| Votes (Legacy) |
|
| Comments (Legacy) |
|
| Proposed (Legacy) |
| N/A |
|
This is an entry on the CVE List, which provides common identifiers for publicly known cybersecurity vulnerabilities. |
|
|
|
For More Information: cve@mitre.org
|