vulnerability
Gentoo Linux: CVE-2018-5244: Xen: Multiple vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:N/C:N/I:N/A:C) | Jan 5, 2018 | Oct 31, 2018 | Mar 31, 2026 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:N/I:N/A:C)
Published
Jan 5, 2018
Added
Oct 31, 2018
Modified
Mar 31, 2026
Description
In Xen 4.10, new infrastructure was introduced as part of an overhaul to how MSR emulation happens for guests. Unfortunately, one tracking structure isn't freed when a vcpu is destroyed. This allows guest OS administrators to cause a denial of service (host OS memory consumption) by rebooting many times.
Solutions
gentoo-linux-upgrade-app-emulation-xengentoo-linux-upgrade-app-emulation-xen-tools
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.