The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemuUpgrade xen | Jul 30, 2024 | Jan 19, 2014 |
| Gentoo Linux | — | Upgrade app-emulations/xen-pvgrub.Upgrade app-emulations/xen.Upgrade app-emulations/xen-tools. | Oct 30, 2017 | Jan 19, 2014 |
| Suse | — | Upgrade xen-doc-pdfUpgrade sle-sdk-releaseUpgrade xen-kmp-desktopUpgrade xen-toolsUpgrade xen-libs-32bitUpgrade xen-kmp-paeUpgrade xen-doc-htmlUpgrade xen-tools-domUUpgrade xen-kmp-defaultUpgrade xen-libsUpgrade xen-develUpgrade xen | Dec 12, 2013 | Dec 10, 2013 |
| Ubuntu | — | Upgrade qemu-system-sparcUpgrade qemu-system-armUpgrade qemu-kvmUpgrade qemu-systemUpgrade qemu-system-x86Upgrade qemu-system-mipsUpgrade qemu-system-miscUpgrade qemu-system-ppc | Nov 8, 2024 | Jan 19, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub