Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
CVSS Details
- CVSS 3.0 Base Score: 3.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xen | May 30, 2017 | May 2, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 13, 2017 |
| Suse | — | Upgrade xen-libsUpgrade xen-tools-domuUpgrade xen-doc-htmlUpgrade xen-toolsUpgrade xen-doc-pdfUpgrade xenUpgrade xen-kmp-defaultUpgrade xen-libs-32bitUpgrade xen-kmp-pae | May 2, 2017 | May 2, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub