GNTTABOP_swap_grant_ref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service (NULL pointer dereference) via a hypercall without a GNTTABOP_setup_table or GNTTABOP_set_version. <a href"http://cwe.mitre.org/data/definitions/476.html">CWE-476: NULL Pointer Dereference</a>
Publication date: Mon, 15 Jun 2015 20:59:00 +0000