Buffer overflow in hw/pt-msi.c in Xen 4.6.x and earlier, when using the qemu-xen-traditional (aka qemu-dm) device model, allows local x86 HVM guest administrators to gain privileges by leveraging a system with access to a passed-through MSI-X capable physical PCI device and MSI-X table entries, related to a "write path."
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xenUpgrade linux-grsecUpgrade qemuUpgrade linux-vanilla. | Aug 30, 2017 | Dec 17, 2015 |
| Debian | — | Upgrade xen | Mar 31, 2017 | Apr 14, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen.Upgrade app-emulation/pvgrub.Upgrade app-emulation/xen-pvgrub. | Oct 30, 2017 | Apr 14, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 17, 2015 |
| Suse | — | Upgrade xen-tools-xendomains-wait-diskUpgrade xen-tools-domUUpgrade xen-develUpgrade xen-toolsUpgrade xen-libsUpgrade xen-kmp-traceUpgrade xen-doc-htmlUpgrade xen-libs-32bitUpgrade xen-kmp-paeUpgrade xen-doc-pdfUpgrade xenUpgrade xen-kmp-default | Mar 24, 2016 | Mar 24, 2016 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Apr 14, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub