The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Sep 20, 2017 | Oct 30, 2015 |
| Debian | — | Upgrade xen | Dec 14, 2015 | Oct 30, 2015 |
| Freebsd | — | Upgrade xen-kernel | Dec 10, 2025 | Nov 11, 2015 |
| Gentoo Linux | — | Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/pvgrub.Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen. | Oct 30, 2017 | Oct 30, 2015 |
| Suse | — | Upgrade xen-doc-pdfUpgrade xen-kmp-defaultUpgrade xen-libsUpgrade xen-doc-htmlUpgrade xen-kmp-paeUpgrade xen-libs-32bitUpgrade xen-toolsUpgrade xen-develUpgrade xen-kmp-traceUpgrade xenUpgrade xen-tools-xendomains-wait-diskUpgrade xen-tools-domU | Dec 18, 2015 | Oct 30, 2015 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Oct 30, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub