An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is not properly restricted.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Feb 15, 2019 | Nov 1, 2018 |
| Debian | — | Upgrade xen | Jul 30, 2024 | Nov 1, 2018 |
| Suse | — | Upgrade xen-toolsUpgrade xen-libsUpgrade xenUpgrade xen-libs-32bitUpgrade xen-doc-htmlUpgrade xen-develUpgrade xen-tools-domUUpgrade xen-tools-xendomains-wait-disk | Dec 12, 2018 | Oct 31, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Nov 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub