CVE-2017-10918: Xen
Critical severity, CVSS 10.0. EPSS: 3.7% chance of exploitation in the next 30 days.
Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.
Affected products
- Xen Xen: up to and including 4.8.1
Published 2017-07-05. Last modified 2026-06-17.