Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which allows local HVM guest users to cause a denial of service (host crash) via unspecified vectors related to "guest VMX instruction execution."
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xen | Jul 30, 2024 | Nov 18, 2013 |
| Gentoo Linux | — | Upgrade app-emulations/xen-pvgrub.Upgrade app-emulations/xen.Upgrade app-emulations/xen-tools. | Oct 30, 2017 | Nov 17, 2013 |
| Suse | — | Upgrade xen-kmp-defaultUpgrade xen-xend-toolsUpgrade xen-tools-domUUpgrade xen-libsUpgrade xen-libs-32bitUpgrade xen-doc-pdfUpgrade xen-develUpgrade xen-doc-htmlUpgrade xenUpgrade xen-kmp-desktopUpgrade xen-toolsUpgrade sle-sdk-releaseUpgrade xen-kmp-pae | Dec 23, 2013 | Nov 17, 2013 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Nov 18, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub