Denial of Service Vulnerability in Xen Hypervisor 4.0.1 and Earlier
CVE-2010-4255

Currently unrated

Key Information:

Vendor
Citrix
Status
Vendor
CVE Published:
25 January 2011

Summary

A vulnerability in the fixup_page_fault function within the Xen Hypervisor 4.0.1 and earlier on 64-bit platforms can be exploited when paravirtualization is enabled. Specifically, the flaw allows guest operating system users to perform crafted memory accesses, leading to a denial of service through a host OS bug. This situation can result in the hypervisor crashing, impacting all virtual machines running on the affected host.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.