CVE-2011-1166: Input Validation
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1166?
CVE-2011-1166 is classified as a high severity vulnerability due to its potential to cause a denial of service by crashing the host.
How do I fix CVE-2011-1166?
To mitigate CVE-2011-1166, upgrade your Xen hypervisor to version 4.0.2 or later, which addresses this vulnerability.
What types of systems are affected by CVE-2011-1166?
CVE-2011-1166 primarily affects local 64-bit paravirtualized (PV) Xen guests on vulnerable versions of the Xen hypervisor.
Can CVE-2011-1166 lead to data loss?
While CVE-2011-1166 mainly causes a host crash, it can lead to service disruption that may indirectly result in data loss.
Is CVE-2011-1166 still a concern for current Xen deployments?
CVE-2011-1166 is not a concern for current Xen deployments using versions after 4.0.2, as the vulnerability has been addressed.