CVE-2017-8903: Xen

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Xen through 4.8.x on 64-bit platforms mishandles page tables after an IRET hypercall, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-213.

Affected products

  • Xen Xen: version 4.8.0 only; version 4.8.1 only

Published 2017-05-11. Last modified 2026-06-17.