Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Oct 30, 2017 | Aug 24, 2017 |
| Debian | — | Upgrade xen | Sep 13, 2017 | Aug 24, 2017 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-tools. | Jan 15, 2018 | Aug 24, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 15, 2017 |
| Suse | — | Upgrade xen-tools-domuUpgrade xen-tools-xendomains-wait-diskUpgrade xen-kmp-paeUpgrade xen-doc-pdfUpgrade xen-develUpgrade xen-toolsUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xen-doc-htmlUpgrade xenUpgrade xen-kmp-default | Sep 1, 2017 | Aug 24, 2017 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Aug 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub