An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays.
CVSS Details
- CVSS 3.0 Base Score: 8.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Sep 20, 2017 | Apr 4, 2017 |
| Debian | — | Upgrade xen | Apr 21, 2017 | Apr 4, 2017 |
| Freebsd | — | Upgrade xen-kernel | Apr 10, 2017 | Apr 6, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 4, 2017 |
| Suse | — | Upgrade xen-doc-htmlUpgrade xen-toolsUpgrade xenUpgrade xen-libs-32bitUpgrade xen-doc-pdfUpgrade xen-kmp-defaultUpgrade xen-kmp-paeUpgrade xen-libsUpgrade xen-develUpgrade xen-tools-domu | Apr 11, 2017 | Apr 4, 2017 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Apr 4, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub