An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialized, that the latter are also ready for use. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system.
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Mar 26, 2024 | Dec 15, 2020 |
| Debian | — | Upgrade xen | Dec 17, 2020 | Dec 15, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Jul 13, 2021 | Dec 15, 2020 |
| Suse | — | Upgrade xen-kmp-defaultUpgrade xen-doc-htmlUpgrade xen-libsUpgrade xen-toolsUpgrade xen-libs-32bitUpgrade xen-develUpgrade xenUpgrade xen-kmp-paeUpgrade xen-tools-domuUpgrade xen-tools-xendomains-wait-disk | Dec 17, 2020 | Dec 15, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 15, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub