An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) Physical-to-Machine (P2M) errors.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-xen | Jan 3, 2018 | Nov 28, 2017 | |
| Debian | debian-upgrade-xen | Dec 5, 2017 | Nov 28, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-app-emulation-xengentoo-linux-upgrade-app-emulation-xen-tools | Jan 15, 2018 | Nov 28, 2017 | |
| Ubuntu | ubuntu-upgrade-xen | Nov 19, 2024 | Nov 28, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub