An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Jun 13, 2018 | May 10, 2018 |
| Debian | — | Upgrade xen | May 17, 2018 | May 10, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-tools. | Oct 31, 2018 | May 10, 2018 |
| Suse | — | Upgrade xen-libs-32bitUpgrade xen-doc-htmlUpgrade xen-tools-xendomains-wait-diskUpgrade xen-libsUpgrade xen-doc-pdfUpgrade xen-develUpgrade xen-toolsUpgrade xen-tools-domUUpgrade xen-kmp-paeUpgrade xenUpgrade xen-kmp-default | May 31, 2018 | May 10, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | May 10, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub