CVE-2017-15592

HIGH

Xen < 4.9.0 - Exposure to Wrong Actor

Title source: rule

Description

An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because self-linear shadow mappings are mishandled for translated guests.

Scores

CVSS v3 8.8
EPSS 0.0010
EPSS Percentile 28.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-668
Status draft

Affected Products (1)

xen/xen < 4.9.0

Timeline

Published Oct 18, 2017
Tracked Since Feb 18, 2026