The evtchn_fifo_set_pending function in Xen 4.4.x allows local guest users to cause a denial of service (host crash) via vectors involving an uninitialized FIFO-based event channel control block when (1) binding or (2) moving an event to a different VCPU.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Xen | Xen | 4.4.0 (including) | 4.4.0 (including) |
| Xen | Xen | 4.4.0-rc1 (including) | 4.4.0-rc1 (including) |
| Xen | Xen | 4.4.1 (including) | 4.4.1 (including) |
| Xen | Ubuntu | devel | * |
| Xen | Ubuntu | trusty | * |
| Xen | Ubuntu | utopic | * |
| Xen-3.3 | Ubuntu | upstream | * |