CVE-2017-8905 PUBLISHED

Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-215.

EPSS 0.09% · 25.0th percentile

Risk Scores

EPSS Score
0.09%
25.0th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSxen0, 4.3.0-1ubuntu1, 4.3.0-1ubuntu2
Ubuntu:16.04:LTSxen0, 4.5.1-0ubuntu1, 4.5.1-0ubuntu2

Timeline

References

Open in Interactive Console →