Vulnerability Details CVE-2019-18844
The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of other mechanisms for propagating error information or diagnostic information), which might allow attackers to cause a denial of service (assertion failure) within pci core. This is fixed in 1.2. 6199e653418e is a mitigation for pre-1.1 versions, whereas 2b3dedfb9ba1 is a mitigation for 1.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-18844
-
-
-
-
-
-
-
-
-
-
cpe:2.3:o:linux:acrn:1.0.1
-
cpe:2.3:o:linux:acrn:1.0.2
-
-
-
-
-
cpe:2.3:o:linux:acrn:2018w20.3-162732p
-
cpe:2.3:o:linux:acrn:2018w20.4-173000p
-
cpe:2.3:o:linux:acrn:2018w20.5-163000p
-
cpe:2.3:o:linux:acrn:2018w20.6-081600p
-
cpe:2.3:o:linux:acrn:2018w21.1-162300p
-
cpe:2.3:o:linux:acrn:2018w21.2-160000p
-
cpe:2.3:o:linux:acrn:2018w21.3-160000p
-
cpe:2.3:o:linux:acrn:2018w21.4-160000p
-
cpe:2.3:o:linux:acrn:2018w21.4-215600p
-
cpe:2.3:o:linux:acrn:2018w21.5-160000p
-
cpe:2.3:o:linux:acrn:2018w22.1-180000p
-
cpe:2.3:o:linux:acrn:2018w22.2-170000p
-
cpe:2.3:o:linux:acrn:2018w22.3-170000p
-
cpe:2.3:o:linux:acrn:2018w22.4-163000p
-
cpe:2.3:o:linux:acrn:2018w22.5-173000p
-
cpe:2.3:o:linux:acrn:2018w22.5-192000p
-
cpe:2.3:o:linux:acrn:2018w23.1-180000p
-
cpe:2.3:o:linux:acrn:2018w23.2-175000p
-
cpe:2.3:o:linux:acrn:2018w23.2-215300p
-
cpe:2.3:o:linux:acrn:2018w23.3-204500p
-
cpe:2.3:o:linux:acrn:2018w23.4-165500p
-
cpe:2.3:o:linux:acrn:2018w23.5-160000p
-
cpe:2.3:o:linux:acrn:2018w23.5-173000p
-
cpe:2.3:o:linux:acrn:2018w24.1-170000p
-
cpe:2.3:o:linux:acrn:2018w24.2-165000p
-
cpe:2.3:o:linux:acrn:2018w24.3-170000p
-
cpe:2.3:o:linux:acrn:2018w24.3-202400p
-
cpe:2.3:o:linux:acrn:2018w24.4-165000p
-
cpe:2.3:o:linux:acrn:2018w24.4-230000p
-
cpe:2.3:o:linux:acrn:2018w24.4-235900p
-
cpe:2.3:o:linux:acrn:2018w24.6-182200p
-
cpe:2.3:o:linux:acrn:2018w24.6-230000p
-
cpe:2.3:o:linux:acrn:2018w24.7-181200p
-
cpe:2.3:o:linux:acrn:2018w25.2-133000p
-
cpe:2.3:o:linux:acrn:2018w25.3-140000f
-
cpe:2.3:o:linux:acrn:2018w25.4-140000p
-
cpe:2.3:o:linux:acrn:2018w25.5-140000p
-
cpe:2.3:o:linux:acrn:2018w26.1-160000p
-
cpe:2.3:o:linux:acrn:2018w26.3-150000p
-
cpe:2.3:o:linux:acrn:2018w26.4-140000p
-
cpe:2.3:o:linux:acrn:2018w26.5-140000p
-
cpe:2.3:o:linux:acrn:2018w27.1-140000p
-
cpe:2.3:o:linux:acrn:2018w27.2-140000p
-
cpe:2.3:o:linux:acrn:2018w27.3-140000p
-
cpe:2.3:o:linux:acrn:2018w27.4-140000p
-
cpe:2.3:o:linux:acrn:2018w27.5-140000p
-
cpe:2.3:o:linux:acrn:2018w28.1-140000p
-
cpe:2.3:o:linux:acrn:2018w28.2-140000f
-
cpe:2.3:o:linux:acrn:2018w28.3-140000p
-
cpe:2.3:o:linux:acrn:2018w28.4-140000p
-
cpe:2.3:o:linux:acrn:2018w28.5-140000p
-
cpe:2.3:o:linux:acrn:2018w29.1-140000p
-
cpe:2.3:o:linux:acrn:2018w29.2-140000p
-
cpe:2.3:o:linux:acrn:2018w29.3-140000p
-
cpe:2.3:o:linux:acrn:2018w29.4-140000p
-
cpe:2.3:o:linux:acrn:2018w29.5-140000p
-
cpe:2.3:o:linux:acrn:2018w30.1-140000p
-
cpe:2.3:o:linux:acrn:2018w30.2-140000p
-
cpe:2.3:o:linux:acrn:2018w30.3-140000p
-
cpe:2.3:o:linux:acrn:2018w30.4-140000p
-
cpe:2.3:o:linux:acrn:2018w30.5-140000p
-
cpe:2.3:o:linux:acrn:2018w31.1-140000p
-
cpe:2.3:o:linux:acrn:2018w31.2-140000f
-
cpe:2.3:o:linux:acrn:2018w31.3-140000p
-
cpe:2.3:o:linux:acrn:2018w31.4-140000f
-
cpe:2.3:o:linux:acrn:2018w31.5-140000f
-
cpe:2.3:o:linux:acrn:2018w32.1-140000p
-
cpe:2.3:o:linux:acrn:2018w32.2-140000p
-
cpe:2.3:o:linux:acrn:2018w32.3-140000p
-
cpe:2.3:o:linux:acrn:2018w32.4-140000p
-
cpe:2.3:o:linux:acrn:2018w32.5-140000p
-
cpe:2.3:o:linux:acrn:2018w33.1-140000f
-
cpe:2.3:o:linux:acrn:2018w33.2-140000p
-
cpe:2.3:o:linux:acrn:2018w33.3-140000p
-
cpe:2.3:o:linux:acrn:2018w33.4-140000p
-
cpe:2.3:o:linux:acrn:2018w33.5-140000p
-
cpe:2.3:o:linux:acrn:2018w34.1-140000p
-
cpe:2.3:o:linux:acrn:2018w34.2-140000p
-
cpe:2.3:o:linux:acrn:2018w34.2-184430p
-
cpe:2.3:o:linux:acrn:2018w34.3-140000p
-
cpe:2.3:o:linux:acrn:2018w34.4-140000p
-
cpe:2.3:o:linux:acrn:2018w34.5-140000p
-
cpe:2.3:o:linux:acrn:2018w35.1-140000p
-
cpe:2.3:o:linux:acrn:2018w35.2-140000p
-
cpe:2.3:o:linux:acrn:2018w35.3-140000p
-
cpe:2.3:o:linux:acrn:2018w35.4-140000p
-
cpe:2.3:o:linux:acrn:2018w35.5-140000p
-
cpe:2.3:o:linux:acrn:2018w36.1-140000f
-
cpe:2.3:o:linux:acrn:2018w36.2-140000p
-
cpe:2.3:o:linux:acrn:2018w36.3-140000p
-
cpe:2.3:o:linux:acrn:2018w36.4-140000f
-
cpe:2.3:o:linux:acrn:2018w36.5-140000p
-
cpe:2.3:o:linux:acrn:2018w37.1-140000f
-
cpe:2.3:o:linux:acrn:2018w37.2-140000p
-
cpe:2.3:o:linux:acrn:2018w37.3-140000f
-
cpe:2.3:o:linux:acrn:2018w37.4-140000p
-
cpe:2.3:o:linux:acrn:2018w37.5-140000p
-
cpe:2.3:o:linux:acrn:2018w38.1-140000p
-
cpe:2.3:o:linux:acrn:2018w38.2-140000f
-
cpe:2.3:o:linux:acrn:2018w38.3-140000p
-
cpe:2.3:o:linux:acrn:2018w38.4-140000p
-
cpe:2.3:o:linux:acrn:2018w39.2-140000p
-
cpe:2.3:o:linux:acrn:2018w39.3-140000p
-
cpe:2.3:o:linux:acrn:2018w39.4-140000p
-
cpe:2.3:o:linux:acrn:2018w39.5-140000p
-
cpe:2.3:o:linux:acrn:2018w39.6-140000p
-
cpe:2.3:o:linux:acrn:2018w40.0-140000p
-
cpe:2.3:o:linux:acrn:2018w41.1-140000p
-
cpe:2.3:o:linux:acrn:2018w41.2-140000p
-
cpe:2.3:o:linux:acrn:2018w41.3-140000f
-
cpe:2.3:o:linux:acrn:2018w41.4-140000p
-
cpe:2.3:o:linux:acrn:2018w41.5-140000f
-
cpe:2.3:o:linux:acrn:2018w42.1-140000f
-
cpe:2.3:o:linux:acrn:2018w42.2-140000p
-
cpe:2.3:o:linux:acrn:2018w42.3-140000f
-
cpe:2.3:o:linux:acrn:2018w42.4-140000f
-
cpe:2.3:o:linux:acrn:2018w42.5-140000p
-
cpe:2.3:o:linux:acrn:2018w43.1-140000p
-
cpe:2.3:o:linux:acrn:2018w43.2-140000f
-
cpe:2.3:o:linux:acrn:2018w43.3-140000f
-
cpe:2.3:o:linux:acrn:2018w43.4-140000p
-
cpe:2.3:o:linux:acrn:2018w43.5-140000p
-
cpe:2.3:o:linux:acrn:2018w44.1-140000p
-
cpe:2.3:o:linux:acrn:2018w44.2-140000p
-
cpe:2.3:o:linux:acrn:2018w44.3-140000p
-
cpe:2.3:o:linux:acrn:2018w44.4-140000p
-
cpe:2.3:o:linux:acrn:2018w44.5-140000f
-
cpe:2.3:o:linux:acrn:2018w45.1-140000p
-
cpe:2.3:o:linux:acrn:2018w45.2-140000f
-
cpe:2.3:o:linux:acrn:2018w45.3-140000p
-
cpe:2.3:o:linux:acrn:2018w45.4-140000p
-
cpe:2.3:o:linux:acrn:2018w45.5-140000p
-
cpe:2.3:o:linux:acrn:2018w46.1-140000p
-
cpe:2.3:o:linux:acrn:2018w46.2-140000p
-
cpe:2.3:o:linux:acrn:2018w46.3-140000p
-
cpe:2.3:o:linux:acrn:2018w46.4-140000p
-
cpe:2.3:o:linux:acrn:2018w46.5-140000p
-
cpe:2.3:o:linux:acrn:2018w47.1-140000p
-
cpe:2.3:o:linux:acrn:2018w47.2-140000p
-
cpe:2.3:o:linux:acrn:2018w47.3-140000p
-
cpe:2.3:o:linux:acrn:2018w47.4-140000p
-
cpe:2.3:o:linux:acrn:2018w47.5-173000p
-
cpe:2.3:o:linux:acrn:2018w48.1-173000p
-
cpe:2.3:o:linux:acrn:2018w48.3-140000p
-
cpe:2.3:o:linux:acrn:2018w48.4-140000p
-
cpe:2.3:o:linux:acrn:2018w48.5-140000p
-
cpe:2.3:o:linux:acrn:2018w49.1-140000p
-
cpe:2.3:o:linux:acrn:2018w49.2-140000p
-
cpe:2.3:o:linux:acrn:2018w49.3-140000p
-
cpe:2.3:o:linux:acrn:2018w49.4-140000p
-
cpe:2.3:o:linux:acrn:2018w49.5-140000p
-
cpe:2.3:o:linux:acrn:2018w50.1-140000p
-
cpe:2.3:o:linux:acrn:2018w50.2-140000p
-
cpe:2.3:o:linux:acrn:2018w50.2-230000p
-
cpe:2.3:o:linux:acrn:2018w50.3-140000p
-
cpe:2.3:o:linux:acrn:2018w50.5-140000p
-
cpe:2.3:o:linux:acrn:2018w51.1-140000f
-
cpe:2.3:o:linux:acrn:2018w51.2-140000p
-
cpe:2.3:o:linux:acrn:2018w51.4-140000p
-
cpe:2.3:o:linux:acrn:2018w51.5-140000p
-
cpe:2.3:o:linux:acrn:2018w52.1-140000p
-
cpe:2.3:o:linux:acrn:2018w52.2-140000p
-
cpe:2.3:o:linux:acrn:2018w52.3-150000p
-
cpe:2.3:o:linux:acrn:2018w52.4-140000p
-
cpe:2.3:o:linux:acrn:2018w52.5-140000p
-
cpe:2.3:o:linux:acrn:2018w52.6-150000p
-
cpe:2.3:o:linux:acrn:2019w01.3-140000p
-
cpe:2.3:o:linux:acrn:2019w01.4-150000p
-
cpe:2.3:o:linux:acrn:2019w01.5-140000p
-
cpe:2.3:o:linux:acrn:2019w01.5-170000p
-
cpe:2.3:o:linux:acrn:2019w02.1-140000p
-
cpe:2.3:o:linux:acrn:2019w02.2-150000p
-
cpe:2.3:o:linux:acrn:2019w02.4-140000p
-
cpe:2.3:o:linux:acrn:2019w02.5-150000p
-
cpe:2.3:o:linux:acrn:2019w03.1-150000p
-
cpe:2.3:o:linux:acrn:2019w03.2-160000p
-
cpe:2.3:o:linux:acrn:2019w03.3-140000p
-
cpe:2.3:o:linux:acrn:2019w03.4-150000p
-
cpe:2.3:o:linux:acrn:2019w03.5-150000p
-
cpe:2.3:o:linux:acrn:2019w04.1-140000p
-
cpe:2.3:o:linux:acrn:2019w04.2-140000p
-
cpe:2.3:o:linux:acrn:2019w04.3-150000p
-
cpe:2.3:o:linux:acrn:2019w04.4-140000p
-
cpe:2.3:o:linux:acrn:2019w04.5-140000f
-
cpe:2.3:o:linux:acrn:2019w04.5-150000p
-
cpe:2.3:o:linux:acrn:2019w05.1-150000p
-
cpe:2.3:o:linux:acrn:2019w05.2-140000p
-
cpe:2.3:o:linux:acrn:2019w05.3-150000p
-
cpe:2.3:o:linux:acrn:2019w05.4-140000p
-
cpe:2.3:o:linux:acrn:2019w07.2-140000f
-
cpe:2.3:o:linux:acrn:2019w07.3-140000f
-
cpe:2.3:o:linux:acrn:2019w07.4-140000p
-
cpe:2.3:o:linux:acrn:2019w07.4-150000p
-
cpe:2.3:o:linux:acrn:2019w07.5-140000p
-
cpe:2.3:o:linux:acrn:2019w08.1-140000p
-
cpe:2.3:o:linux:acrn:2019w08.3-150000p
-
cpe:2.3:o:linux:acrn:2019w08.4-140000p
-
cpe:2.3:o:linux:acrn:2019w08.5-140000p
-
cpe:2.3:o:linux:acrn:2019w09.2-140000p
-
cpe:2.3:o:linux:acrn:2019w09.2-150000p
-
cpe:2.3:o:linux:acrn:2019w09.3-150000p
-
cpe:2.3:o:linux:acrn:2019w09.4-150000p
-
cpe:2.3:o:linux:acrn:2019w09.4-153000p
-
cpe:2.3:o:linux:acrn:2019w09.5-140000p
-
cpe:2.3:o:linux:acrn:2019w10.2-140000p
-
cpe:2.3:o:linux:acrn:2019w10.3-140000p
-
cpe:2.3:o:linux:acrn:2019w10.3-150000p
-
cpe:2.3:o:linux:acrn:2019w10.4-150000p
-
cpe:2.3:o:linux:acrn:2019w10.5-140000p
-
cpe:2.3:o:linux:acrn:2019w11.1-140000p
-
cpe:2.3:o:linux:acrn:2019w11.1-150000p
-
cpe:2.3:o:linux:acrn:2019w11.1-153000p
-
cpe:2.3:o:linux:acrn:2019w11.3-150000p
-
cpe:2.3:o:linux:acrn:2019w11.3-153000p
-
cpe:2.3:o:linux:acrn:2019w11.4-140000p
-
cpe:2.3:o:linux:acrn:2019w11.5-140000p
-
cpe:2.3:o:linux:acrn:2019w12.1-150000p
-
cpe:2.3:o:linux:acrn:2019w12.2-140000p
-
cpe:2.3:o:linux:acrn:2019w12.2-150000p
-
cpe:2.3:o:linux:acrn:2019w12.3-150000p
-
cpe:2.3:o:linux:acrn:2019w12.4-140000f
-
cpe:2.3:o:linux:acrn:2019w12.5-140000f
-
cpe:2.3:o:linux:acrn:2019w13.1-140000f
-
cpe:2.3:o:linux:acrn:2019w13.2-140000p
-
cpe:2.3:o:linux:acrn:2019w13.3-140000p
-
cpe:2.3:o:linux:acrn:2019w13.4-140000p
-
cpe:2.3:o:linux:acrn:2019w13.5-140000p
-
cpe:2.3:o:linux:acrn:2019w14.1-140000p
-
cpe:2.3:o:linux:acrn:2019w14.3-140000p
-
cpe:2.3:o:linux:acrn:2019w14.4-140000p
-
cpe:2.3:o:linux:acrn:2019w15.1-140000p
-
cpe:2.3:o:linux:acrn:2019w15.3-140000f
-
cpe:2.3:o:linux:acrn:2019w15.4-140000p
-
cpe:2.3:o:linux:acrn:2019w15.5-140000p
-
cpe:2.3:o:linux:acrn:2019w16.1-140000p
-
cpe:2.3:o:linux:acrn:2019w16.2-140000p
-
cpe:2.3:o:linux:acrn:2019w16.3-140000p
-
cpe:2.3:o:linux:acrn:2019w16.4-140000p
-
cpe:2.3:o:linux:acrn:2019w16.5-140000p
-
cpe:2.3:o:linux:acrn:2019w16.5-150000p
-
cpe:2.3:o:linux:acrn:2019w17.2-160000p
-
cpe:2.3:o:linux:acrn:2019w17.4-160000p
-
cpe:2.3:o:linux:acrn:2019w18.7-140000p
-
cpe:2.3:o:linux:acrn:2019w19.1-140000p
-
cpe:2.3:o:linux:acrn:2019w19.2-140000p
-
cpe:2.3:o:linux:acrn:2019w19.3-140000p
-
cpe:2.3:o:linux:acrn:2019w19.4-140000p
-
cpe:2.3:o:linux:acrn:2019w19.5-140000p
-
cpe:2.3:o:linux:acrn:2019w20.1-140000p
-
cpe:2.3:o:linux:acrn:2019w20.2-140000p
-
cpe:2.3:o:linux:acrn:2019w20.3-140000f
-
cpe:2.3:o:linux:acrn:2019w20.3-150000p
-
cpe:2.3:o:linux:acrn:2019w20.4-140000p
-
cpe:2.3:o:linux:acrn:2019w20.5-140000p
-
cpe:2.3:o:linux:acrn:2019w21.1-140000p
-
cpe:2.3:o:linux:acrn:2019w21.2-140000p
-
cpe:2.3:o:linux:acrn:2019w21.3-140000p
-
cpe:2.3:o:linux:acrn:2019w21.4-140000p
-
cpe:2.3:o:linux:acrn:2019w21.5-140000p
-
cpe:2.3:o:linux:acrn:2019w21.5-150000p
-
cpe:2.3:o:linux:acrn:2019w22.1-140000p
-
cpe:2.3:o:linux:acrn:2019w22.2-140000p
-
cpe:2.3:o:linux:acrn:2019w22.3-140000p
-
cpe:2.3:o:linux:acrn:2019w22.4-140000p
-
cpe:2.3:o:linux:acrn:2019w22.5-140000p
-
cpe:2.3:o:linux:acrn:2019w23.1-140000p
-
cpe:2.3:o:linux:acrn:2019w23.4-140000p
-
cpe:2.3:o:linux:acrn:2019w24.3-150000p
-
cpe:2.3:o:linux:acrn:2019w24.4-140000p