The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMU_MACHPHYS_UPDATE.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xen | Jul 30, 2024 | Nov 24, 2014 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Oct 30, 2017 | Nov 24, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 20, 2014 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xen-doc-pdfUpgrade xen-toolsUpgrade xen-develUpgrade xen-kmp-defaultUpgrade xen-tools-domUUpgrade xenUpgrade xen-doc-htmlUpgrade xen-kmp-trace | Dec 18, 2015 | Nov 24, 2014 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Nov 24, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub