An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
https://www.debian.org/security/2019/dsa-4369
https://support.citrix.com/article/CTX239432
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXC6BME7SXJI2ZIATNXCAH7RGPI4UKTT/
http://www.securityfocus.com/bid/106182
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00072.html
https://xenbits.xen.org/xsa/advisory-275.html
https://lists.debian.org/debian-lts-announce/2019/10/msg00008.html
Source: Mitre, NVD
Published: 2018-12-08
Updated: 2024-11-21
Base Score: 6.9
Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C
Severity: Medium
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity: High
EPSS: 0.00108