CVE-2017-8905: Xen

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-215.

Affected products

  • Xen Xen: version 4.6.0 only; version 4.6.1 only; version 4.6.2 only; version 4.6.3 only; version 4.6.4 only; version 4.6.5 only

Published 2017-05-11. Last modified 2026-06-17.