Xen 3.3.x through 4.5.x does not properly restrict write access to the host MSI message data field, which allows local x86 HVM guest administrators to cause a denial of service (host interrupt handling confusion) via vectors related to qemu and accessing spanning multiple fields.
CVSS Details
- CVSS 3.1 Base Score: 6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xenUpgrade qemu | Jul 30, 2024 | Jun 3, 2015 |
| Freebsd | — | Upgrade xen-tools | Dec 10, 2025 | Jul 11, 2015 |
| Gentoo Linux | — | Upgrade app-emulation/pvgrub.Upgrade app-emulation/xen.Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/xen-tools. | Oct 30, 2017 | Jun 3, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 2, 2015 |
| Suse | — | Upgrade xen-kmp-traceUpgrade xen-doc-htmlUpgrade xen-tools-domUUpgrade xen-develUpgrade xenUpgrade xen-tools-xendomains-wait-diskUpgrade xen-toolsUpgrade xen-kmp-defaultUpgrade xen-doc-pdfUpgrade xen-kmp-paeUpgrade xen-libsUpgrade xen-libs-32bit | Dec 18, 2015 | Jun 3, 2015 |
| Ubuntu | — | Upgrade qemu-system-armUpgrade qemu-kvmUpgrade qemu-system-mipsUpgrade qemu-system-aarch64Upgrade qemu-system-ppcUpgrade qemu-system-miscUpgrade qemu-system-x86Upgrade qemu-systemUpgrade qemu-system-sparc | Nov 8, 2024 | Jun 3, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub