Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038735 | vdb entry third party advisory |
http://www.securityfocus.com/bid/99160 | vdb entry tool signature |
https://security.gentoo.org/glsa/201708-03 | vendor advisory |
https://xenbits.xen.org/xsa/advisory-225.html | mailing list vendor advisory mitigation |