The evtchn_fifo_set_pending function in Xen 4.4.x allows local guest users to cause a denial of service (host crash) via vectors involving an uninitialized FIFO-based event channel control block when (1) binding or (2) moving an event to a different VCPU.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xen | Jul 30, 2024 | Jan 12, 2015 |
| Suse | — | Upgrade xen-libs-32bitUpgrade xen-toolsUpgrade xen-kmp-defaultUpgrade xen-libsUpgrade xenUpgrade xen-develUpgrade xen-tools-domUUpgrade xen-doc-html | Dec 9, 2016 | Jan 12, 2015 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Jan 12, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub