An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Feb 15, 2019 | Dec 8, 2018 |
| Debian | — | Upgrade xen | Jan 16, 2019 | Dec 7, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 8, 2018 |
| Suse | — | Upgrade xen-doc-htmlUpgrade xenUpgrade xen-develUpgrade xen-libsUpgrade xen-tools-xendomains-wait-diskUpgrade xen-libs-32bitUpgrade xen-tools-domUUpgrade xen-kmp-defaultUpgrade xen-kmp-paeUpgrade xen-tools | Dec 12, 2018 | Dec 7, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 8, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub