The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xenserver | Citrix | * | 6.5 (including) |
Xen | Ubuntu | devel | * |
Xen | Ubuntu | precise | * |
Xen | Ubuntu | trusty | * |
Xen | Ubuntu | upstream | * |
Xen | Ubuntu | vivid | * |
Xen | Ubuntu | wily | * |