Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
| Software | From | Fixed in |
|---|---|---|
| xen / xen | 4.6.0 | 4.6.0.x |
| xen / xen | 4.7.0 | 4.7.0.x |
| xen / xen | 4.6.3 | 4.6.3.x |
| xen / xen | 4.5.2 | 4.5.2.x |
| xen / xen | 4.6.1 | 4.6.1.x |
| xen / xen | 4.5.3 | 4.5.3.x |
| xen / xen | 4.5.1 | 4.5.1.x |
| xen / xen | 4.5.0 | 4.5.0.x |
| citrix / xenserver | 6.5.0-sp1 | 6.5.0-sp1.x |
| citrix / xenserver | 7.0 | 7.0.x |
| citrix / xenserver | 6.0.2 | 6.0.2.x |
| citrix / xenserver | 6.0 | 6.0.x |
| citrix / xenserver | 6.2.0-sp1 | 6.2.0-sp1.x |
| citrix / xenserver | 6.1 | 6.1.x |