CVE-2017-17044
MEDIUMXen <4.9.x - DoS
Title source: llmDescription
An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and host OS hang) by leveraging the mishandling of Populate on Demand (PoD) errors.
References (9)
Scores
CVSS v3
6.5
EPSS
0.0005
EPSS Percentile
15.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Classification
CWE
CWE-755
CWE-754
CWE-835
Status
draft
Affected Products (1)
xen/xen
< 4.9.1
Timeline
Published
Nov 28, 2017
Tracked Since
Feb 18, 2026