Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/201612-56 | vendor advisory |
http://www.securityfocus.com/bid/94475 | vdb entry |
http://xenbits.xen.org/xsa/advisory-196.html | patch vendor advisory |
http://www.securitytracker.com/id/1037345 | vdb entry |