SB2020040420 - Infinite loop in xen (Alpine package)
Published: April 4, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Infinite loop (CVE-ID: CVE-2019-17350)
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchange operation.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=e42bcd9d2c39e861c980adebf91418ddbe72bd21
- https://git.alpinelinux.org/aports/commit/?id=c49084a961893d69e5cdba0b5a8072217ba8be67
- https://git.alpinelinux.org/aports/commit/?id=9c1b7583516c05d0c924a44cbf3e3b651c58fa8e
- https://git.alpinelinux.org/aports/commit/?id=a80b91506c3d39fd6d12fe94a65dd4a313261546