Xen
cpe:2.3:a:xen:xen:*:*:*:*:*:*:*, +2 more
- >= 4.13
A NULL pointer dereference vulnerability has been identified in the Xen hypervisor's Viridian interface, specifically in versions 4.13 and newer. This vulnerability arises when updating the reference Time Stamp Counter (TSC) area, leading to a denial-of-service condition that affects the entire host.
Exploitation of this vulnerability causes a denial-of-service condition on the host, potentially leading to information leaks or unauthorized privilege escalation.
To address this vulnerability, users can apply the patches provided in the Xen Security Advisory XSA-472. Instructions for applying these patches are included in the advisory.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.