CVE-2019-17351: Linux Kernel

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef36ab967c7.

Affected products

  • Linux Linux Kernel: before 5.2.3 (fixed in 5.2.3)
  • Xen Xen: up to and including 4.12.1

Published 2019-10-08. Last modified 2026-06-17.