The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages when logging the new callback method, which allows local HVM guest OS users to cause a denial of service via a large number of changes to the callback method (HVM_PARAM_CALLBACK_IRQ).
CVSS Details
- CVSS 3.1 Base Score: 5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xenUpgrade linux-grsecUpgrade qemuUpgrade linux-vanilla. | Aug 30, 2017 | Dec 17, 2015 |
| Debian | — | Upgrade xen | Mar 31, 2017 | Jan 8, 2016 |
| Suse | — | Upgrade xen-doc-htmlUpgrade xen-develUpgrade xen-toolsUpgrade xen-tools-xendomains-wait-diskUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xen-tools-domUUpgrade xen | Dec 9, 2016 | Jan 8, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub