Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error messages, which allows local x86 HVM guests to cause a denial of service (host disk consumption) via certain invalid operations.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xenUpgrade qemu | Jul 30, 2024 | Jun 3, 2015 |
| Freebsd | — | Upgrade xen-tools | Dec 10, 2025 | Jul 11, 2015 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/pvgrub.Upgrade app-emulation/xen. | Oct 30, 2017 | Jun 3, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 2, 2015 |
| Suse | — | Upgrade xen-libs-32bitUpgrade xen-kmp-paeUpgrade xen-toolsUpgrade xen-libsUpgrade xen-doc-pdfUpgrade xen-tools-xendomains-wait-diskUpgrade xen-develUpgrade xen-kmp-traceUpgrade xen-tools-domUUpgrade xen-kmp-defaultUpgrade xen-doc-htmlUpgrade xen | Dec 18, 2015 | Jun 3, 2015 |
| Ubuntu | — | Upgrade qemu-system-aarch64Upgrade qemu-system-ppcUpgrade qemu-system-miscUpgrade qemu-system-x86Upgrade qemu-system-sparcUpgrade qemu-system-armUpgrade qemu-kvmUpgrade qemu-systemUpgrade qemu-system-mips | Nov 8, 2024 | Jun 3, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub