An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
CVSS Details
- CVSS 3.1 Base Score: 5.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Jun 13, 2018 | Apr 27, 2018 |
| Debian | — | Upgrade xen | May 17, 2018 | Apr 27, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-tools. | Oct 31, 2018 | Apr 27, 2018 |
| Suse | — | Upgrade xen-toolsUpgrade xen-tools-xendomains-wait-diskUpgrade xen-develUpgrade xen-doc-htmlUpgrade xen-kmp-paeUpgrade xen-doc-pdfUpgrade xenUpgrade xen-tools-domUUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xen-kmp-default | May 10, 2018 | Apr 27, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub