CVE-2011-2901 describes an off-by-one error in the __addr_ok macro within Xen 3.3 and earlier, allowing local 64-bit PV guest administrators to trigger a host crash through specific hypercalls. With a CVSS score of 5.5, this vulnerability is of medium severity, requiring authenticated access within the adjacent network to achieve a denial of service. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion, indicating a low likelihood of real-world impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | ||
3.0.2CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.0.2:*:*:*:*:*:*:* | ||
3.0.3CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.0.3:*:*:*:*:*:*:* | ||
3.0.4CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.0.4:*:*:*:*:*:*:* | ||
3.1.3CPE matchmatch criteria | cpe:2.3:o:xen:xen:3.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:S/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.