Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-215.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Sep 20, 2017 | May 11, 2017 |
| Debian | — | Upgrade xen | May 30, 2017 | May 11, 2017 |
| Gentoo Linux | — | Upgrade app-emulation/xen-pvgrub.Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen. | Oct 30, 2017 | May 11, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 2, 2017 |
| Suse | — | Upgrade xen-doc-htmlUpgrade xen-tools-domUUpgrade xenUpgrade xen-develUpgrade xen-kmp-paeUpgrade xen-libs-32bitUpgrade xen-toolsUpgrade xen-kmp-defaultUpgrade xen-doc-pdfUpgrade xen-libs | Jun 30, 2017 | May 11, 2017 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | May 11, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub