CVE-2018-19967: Debian Linux

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions associated with the KACQUIRE instruction prefix.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Xen Xen: up to and including 4.11.1

Published 2018-12-08. Last modified 2026-06-17.