A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xenstored daemon may crash, resulting in a DoS of any parts of the system relying on it (including domain creation / destruction, ballooning, device changes, etc.).
CVSS Details
- CVSS 3.0 Base Score: 5.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Oct 26, 2017 | Sep 12, 2017 |
| Debian | — | Upgrade xen | Nov 29, 2017 | Sep 12, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 12, 2017 |
| Suse | — | Upgrade xen-toolsUpgrade xen-libsUpgrade xenUpgrade xen-libs-32bitUpgrade xen-kmp-defaultUpgrade xen-doc-pdfUpgrade xen-tools-domUUpgrade xen-doc-htmlUpgrade xen-develUpgrade xen-kmp-pae | Sep 13, 2017 | Sep 12, 2017 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Sep 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub