An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do not. In particular, Branch Trace Store is not virtualised by the processor, and software has to be careful to configure it suitably not to lock up the core. As a result, it must only be available to fully trusted guests. Unfortunately, in the case that vPMU is disabled, all value checking was skipped, allowing the guest to choose any MSR_DEBUGCTL setting it likes. A malicious or buggy guest administrator (on Intel x86 HVM or PVH) can lock up the entire host, causing a Denial of Service.
CVSS Details
- CVSS 3.1 Base Score: 6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Aug 22, 2024 | Aug 17, 2018 |
| Debian | — | Upgrade xen | Feb 25, 2019 | Aug 17, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen. | Oct 31, 2018 | Aug 17, 2018 |
| Suse | — | Upgrade xen-develUpgrade xenUpgrade xen-toolsUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xen-doc-htmlUpgrade xen-tools-domUUpgrade xen-tools-xendomains-wait-disk | Oct 24, 2018 | Aug 17, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Aug 17, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub