CVE-2010-3699 describes a denial-of-service vulnerability in Xen 3.x, specifically affecting Citrix Xen, where guest OS users can trigger a kernel thread leak in the backend driver (netback, blkback, or blktap). This flaw can lead to system instability, preventing proper shutdown of devices or guest OSes, causing hangs in zenwatch, or disrupting xm commands. With a low CVSS score of 2.7, the attack requires authenticated access and local network proximity (AV:A/AC:L/Au:S), resulting in partial availability impact (A:P). There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.2CPE matchmatch criteria | cpe:2.3:a:citrix:xen:3.0.2:*:*:*:*:*:*:* | ||
3.0.3CPE matchmatch criteria | cpe:2.3:a:citrix:xen:3.0.3:*:*:*:*:*:*:* | ||
3.0.4CPE matchmatch criteria | cpe:2.3:a:citrix:xen:3.0.4:*:*:*:*:*:*:* | ||
3.1.3CPE matchmatch criteria | cpe:2.3:a:citrix:xen:3.1.3:*:*:*:*:*:*:* | ||
3.1.4CPE matchmatch criteria | cpe:2.3:a:citrix:xen:3.1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:S/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.