An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or gain privileges by triggering a grant-table transition from v2 to v1.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Mar 20, 2018 | Feb 27, 2018 |
| Debian | — | Upgrade xen | Mar 5, 2018 | Feb 27, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-tools. | Oct 31, 2018 | Feb 27, 2018 |
| Suse | — | Upgrade xen-libsUpgrade xen-develUpgrade xen-tools-xendomains-wait-diskUpgrade xen-doc-pdfUpgrade xen-doc-htmlUpgrade xen-kmp-defaultUpgrade xen-tools-domUUpgrade xen-libs-32bitUpgrade xenUpgrade xen-toolsUpgrade xen-kmp-pae | Mar 15, 2018 | Feb 27, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub