Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
2016-08-02T16:59:09.133
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 6.2 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:C
3.9
6.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | xen | xen | 4.5.0 | Yes |
| Operating System | xen | xen | 4.5.1 | Yes |
| Operating System | xen | xen | 4.5.2 | Yes |
| Operating System | xen | xen | 4.5.3 | Yes |
| Operating System | xen | xen | 4.6.0 | Yes |
| Operating System | xen | xen | 4.6.1 | Yes |
| Operating System | xen | xen | 4.6.3 | Yes |
| Operating System | xen | xen | 4.7.0 | Yes |
| Application | citrix | xenserver | 6.0 | Yes |
| Application | citrix | xenserver | 6.0.2 | Yes |
| Application | citrix | xenserver | 6.1 | Yes |
| Application | citrix | xenserver | 6.2.0 | Yes |
| Application | citrix | xenserver | 6.5.0 | Yes |
| Application | citrix | xenserver | 7.0 | Yes |