Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Sep 20, 2017 | Feb 22, 2017 |
| Debian | — | Upgrade xen | Jul 30, 2024 | Feb 22, 2017 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/xen-tools. | Oct 30, 2017 | Feb 22, 2017 |
| Suse | — | Upgrade xen-tools-domuUpgrade xenUpgrade xen-tools-xendomains-wait-diskUpgrade xen-develUpgrade xen-toolsUpgrade xen-libsUpgrade xen-libs-32bitUpgrade xen-doc-htmlUpgrade xen-kmp-default | Dec 9, 2016 | Dec 9, 2016 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Feb 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub