Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Sep 20, 2017 | Feb 22, 2017 |
| Debian | — | Upgrade xen | Jul 30, 2024 | Feb 22, 2017 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/xen. | Oct 30, 2017 | Feb 22, 2017 |
| Suse | — | Upgrade xen-doc-htmlUpgrade xen-libsUpgrade xen-kmp-defaultUpgrade xen-libs-32bitUpgrade xen-tools-xendomains-wait-diskUpgrade xenUpgrade xen-tools-domUUpgrade xen-develUpgrade xen-tools | Dec 9, 2016 | Dec 9, 2016 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Feb 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub