The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GFN range.
CVSS Details
- CVSS 3.1 Base Score: 5.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xen | Jul 30, 2024 | Aug 28, 2013 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Oct 30, 2017 | Aug 28, 2013 |
| Suse | — | Upgrade xen-doc-pdfUpgrade xen-kmp-paeUpgrade xenUpgrade xen-libs-32bitUpgrade xen-kmp-defaultUpgrade sle-sdk-releaseUpgrade xen-tools-domUUpgrade xen-kmp-desktopUpgrade xen-toolsUpgrade xen-develUpgrade xen-libsUpgrade xen-doc-htmlUpgrade xen-xend-toolsUpgrade xen-kmp-trace | Feb 17, 2015 | Aug 28, 2013 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Aug 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub