CVE-2018-10472: Debian Linux
Medium severity, CVSS 5.6. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
Affected products
Published 2018-04-27. Last modified 2026-06-17.