The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly release locks, which might allow guest OS administrators to cause a denial of service (deadlock or host crash) via unspecified vectors, related to XENMEM_exchange error handling.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xenUpgrade linux-grsecUpgrade qemuUpgrade linux-vanilla. | Aug 30, 2017 | Dec 17, 2015 |
| Debian | — | Upgrade xen | Mar 22, 2016 | Dec 17, 2015 |
| Freebsd | — | Upgrade xen-kernel | Dec 10, 2025 | Jan 6, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/pvgrub.Upgrade app-emulation/xen-tools. | Oct 30, 2017 | Dec 17, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 8, 2015 |
| Suse | — | Upgrade xen-tools-domUUpgrade xen-kmp-traceUpgrade xen-libsUpgrade xen-develUpgrade xenUpgrade xen-kmp-defaultUpgrade xen-doc-htmlUpgrade xen-kmp-paeUpgrade xen-libs-32bitUpgrade xen-tools-xendomains-wait-diskUpgrade xen-doc-pdfUpgrade xen-tools | Jan 4, 2016 | Dec 17, 2015 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Dec 17, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub