When a transaction is committed, C Xenstored will first check the quota is correct before attempting to commit any nodes. It would be possible that accounting is temporarily negative if a node has been removed outside of the transaction.
Unfortunately, some versions of C Xenstored are assuming that the quota cannot be negative and are using assert() to confirm it. This will lead to C Xenstored crash when tools are built without -DNDEBUG (this is the default).
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Mar 26, 2024 | Jan 5, 2024 |
| Debian | — | Upgrade xen | Jul 30, 2024 | Jan 5, 2024 |
| Dell Powerstore Dsa2024120 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Mar 26, 2024 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Sep 23, 2024 | Jan 5, 2024 |
| Suse | — | Upgrade xen-toolsUpgrade xen-tools-xendomains-wait-diskUpgrade xen-develUpgrade xen-libsUpgrade xen-libs-32bitUpgrade xenUpgrade xen-doc-htmlUpgrade xen-tools-domU | Oct 13, 2023 | Oct 12, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub