An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or gain privileges by triggering a grant-table transition from v2 to v1.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Mar 20, 2018 | Feb 27, 2018 |
| Debian | — | Upgrade xen | Mar 5, 2018 | Feb 27, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen. | Oct 31, 2018 | Feb 27, 2018 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-toolsUpgrade xenUpgrade xen-doc-htmlUpgrade xen-tools-domUUpgrade xen-doc-pdfUpgrade xen-develUpgrade xen-libsUpgrade xen-tools-xendomains-wait-diskUpgrade xen-kmp-defaultUpgrade xen-libs-32bit | Mar 15, 2018 | Feb 27, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub