Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Sep 20, 2017 | Feb 22, 2017 |
| Debian | — | Upgrade xen | Jul 30, 2024 | Feb 22, 2017 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen.Upgrade app-emulation/xen-pvgrub. | Oct 30, 2017 | Feb 22, 2017 |
| Suse | — | Upgrade xen-tools-xendomains-wait-diskUpgrade xenUpgrade xen-toolsUpgrade xen-tools-domuUpgrade xen-develUpgrade xen-kmp-defaultUpgrade xen-libsUpgrade xen-libs-32bitUpgrade xen-doc-html | Dec 9, 2016 | Dec 9, 2016 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Feb 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub