The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xen | Mar 31, 2017 | Apr 1, 2015 |
| Freebsd | — | Upgrade xen-toolsUpgrade xen-kernel | Dec 10, 2025 | Jul 11, 2015 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Oct 30, 2017 | Apr 1, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 31, 2015 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-doc-htmlUpgrade xen-libs-32bitUpgrade xen-kmp-defaultUpgrade xenUpgrade xen-tools-domUUpgrade xen-toolsUpgrade xen-libsUpgrade xen-devel | Dec 18, 2015 | Apr 1, 2015 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Apr 1, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub