An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Mar 20, 2018 | Feb 27, 2018 |
| Debian | — | Upgrade xen | Mar 5, 2018 | Feb 27, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen. | Oct 31, 2018 | Feb 27, 2018 |
| Suse | — | Upgrade xen-tools-xendomains-wait-diskUpgrade xen-tools-domUUpgrade xen-develUpgrade xen-doc-htmlUpgrade xen-toolsUpgrade xen-libs-32bitUpgrade xen-libsUpgrade xen | May 10, 2018 | Feb 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub