Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.
CVSS Details
- CVSS 3.0 Base Score: 6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Aug 30, 2017 | Jan 26, 2017 |
| Debian | — | Upgrade xen | Mar 31, 2017 | Jan 26, 2017 |
| Freebsd | — | Upgrade xen-kernel | Dec 22, 2016 | Dec 22, 2016 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/xen-tools. | Oct 30, 2017 | Jan 26, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 21, 2016 |
| Suse | — | Upgrade xenUpgrade xen-doc-htmlUpgrade xen-develUpgrade xen-libsUpgrade xen-kmp-defaultUpgrade xen-tools-domUUpgrade xen-tools-xendomains-wait-diskUpgrade xen-libs-32bitUpgrade xen-doc-pdfUpgrade xen-kmp-paeUpgrade xen-tools | Dec 24, 2016 | Dec 21, 2016 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Jan 26, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub