Bug 1610548 (CVE-2018-15468)

Summary: CVE-2018-15468 xen: x86 Incorrect MSR_DEBUGCTL handling lets guests enable BTS (XSA-269)
Product: [Other] Security Response Reporter: Laura Pardo <lpardo>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ailan, drjones, imammedo, jforbes, knoel, m.a.young, mrezanin, pbonzini, rkrcmar, robinlee.sysu, security-response-team, vkuznets, xen-maint
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-10-09 12:01:10 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1616077    
Bug Blocks: 1610551    

Description Laura Pardo 2018-07-31 21:48:16 UTC
A flaw was found in xen. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do not. In particular, Branch Trace Store is not virtualised by the processor, and software has to be careful to configure it suitably not to lock up the core. A malicious or buggy guest administrator can lock up the entire host, causing a Denial of Service.

Comment 1 Laura Pardo 2018-08-14 21:48:09 UTC
Created xen tracking bugs for this issue:

Affects: fedora-all [bug 1616077]