An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
CVSS Details
- CVSS 3.1 Base Score: 5.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-xen | Jun 13, 2018 | Apr 27, 2018 | |
| Debian | debian-upgrade-xen | May 17, 2018 | Apr 27, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-app-emulation-xengentoo-linux-upgrade-app-emulation-xen-tools | Oct 31, 2018 | Apr 27, 2018 | |
| Suse | — | suse-upgrade-xensuse-upgrade-xen-develsuse-upgrade-xen-doc-htmlsuse-upgrade-xen-doc-pdfsuse-upgrade-xen-kmp-defaultsuse-upgrade-xen-kmp-paesuse-upgrade-xen-libssuse-upgrade-xen-libs-32bitsuse-upgrade-xen-toolssuse-upgrade-xen-tools-domususe-upgrade-xen-tools-xendomains-wait-disk | May 10, 2018 | Apr 27, 2018 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Apr 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub