Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.
2017-07-05T01:29:00.737
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:N/A:C
10.0
9.2