Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xen | Xen | 4.5.0 (including) | 4.5.0 (including) |
Xen | Xen | 4.5.1 (including) | 4.5.1 (including) |
Xen | Xen | 4.5.2 (including) | 4.5.2 (including) |
Xen | Xen | 4.5.3 (including) | 4.5.3 (including) |
Xen | Xen | 4.5.5 (including) | 4.5.5 (including) |
Xen | Xen | 4.6.0 (including) | 4.6.0 (including) |
Xen | Xen | 4.6.1 (including) | 4.6.1 (including) |
Xen | Xen | 4.6.3 (including) | 4.6.3 (including) |
Xen | Xen | 4.6.4 (including) | 4.6.4 (including) |
Xen | Xen | 4.7.0 (including) | 4.7.0 (including) |
Xen | Xen | 4.7.1 (including) | 4.7.1 (including) |
Xen | Ubuntu | devel | * |
Xen | Ubuntu | xenial | * |
Xen | Ubuntu | yakkety | * |
Xen | Ubuntu | zesty | * |