An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Jun 13, 2018 | Apr 27, 2018 |
| Debian | — | Upgrade xen | May 17, 2018 | Apr 27, 2018 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen. | Oct 31, 2018 | Apr 27, 2018 |
| Suse | — | Upgrade xen-doc-pdfUpgrade xen-kmp-defaultUpgrade xen-libs-32bitUpgrade xen-tools-xendomains-wait-diskUpgrade xen-libsUpgrade xen-toolsUpgrade xen-kmp-paeUpgrade xen-doc-htmlUpgrade xen-develUpgrade xen-tools-domuUpgrade xen | May 10, 2018 | Apr 27, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub