An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L4 pagetable freeing.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Mar 20, 2018 | Feb 27, 2018 |
| Debian | — | Upgrade xen | Mar 5, 2018 | Feb 27, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen. | Oct 31, 2018 | Feb 27, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 27, 2018 |
| Suse | — | Upgrade xen-kmp-defaultUpgrade xen-tools-xendomains-wait-diskUpgrade xen-libsUpgrade xen-doc-pdfUpgrade xen-kmp-paeUpgrade xen-toolsUpgrade xen-doc-htmlUpgrade xen-tools-domuUpgrade xen-develUpgrade xenUpgrade xen-libs-32bit | Mar 15, 2018 | Feb 27, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub