An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) Physical-to-Machine (P2M) errors.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Jan 3, 2018 | Nov 28, 2017 |
| Debian | — | Upgrade xen | Dec 5, 2017 | Nov 28, 2017 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-tools. | Jan 15, 2018 | Nov 28, 2017 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Nov 28, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub