Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Sep 20, 2017 | Feb 22, 2017 |
| Debian | — | Upgrade xen | Jul 30, 2024 | Feb 22, 2017 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen.Upgrade app-emulation/xen-pvgrub. | Oct 30, 2017 | Feb 22, 2017 |
| Suse | — | Upgrade xen-develUpgrade xen-tools-domUUpgrade xen-toolsUpgrade xenUpgrade xen-libsUpgrade xen-tools-xendomains-wait-diskUpgrade xen-kmp-defaultUpgrade xen-doc-htmlUpgrade xen-libs-32bit | Dec 9, 2016 | Dec 9, 2016 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Feb 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub