The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
CVSS Details
- CVSS 3.1 Base Score: 6.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade linux-vanilla.Upgrade qemuUpgrade xenUpgrade linux-grsec | Aug 30, 2017 | Dec 17, 2015 |
| Debian | — | Upgrade xen | Mar 22, 2016 | Jan 22, 2016 |
| Freebsd | — | Upgrade xen-kernel | Dec 10, 2025 | Feb 28, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 20, 2016 |
| Suse | — | Upgrade xen-libs-32bitUpgrade xen-doc-pdfUpgrade xenUpgrade xen-doc-htmlUpgrade xen-toolsUpgrade xen-tools-domUUpgrade xen-libsUpgrade xen-kmp-traceUpgrade xen-kmp-defaultUpgrade xen-develUpgrade xen-kmp-paeUpgrade xen-tools-xendomains-wait-disk | Mar 28, 2016 | Jan 22, 2016 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Jan 22, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub