CVE-2017-8904: Xen

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.

Affected products

  • Xen Xen: version 4.8.0 only; version 4.8.1 only

Published 2017-05-11. Last modified 2026-06-17.