Xen up to and including 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
xen xen |