The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (NULL pointer dereference and host OS crash) by creating concurrent domains and holding references to them, related to VMID exhaustion. <a href"http://cwe.mitre.org/data/definitions/476.html">CWE-476: NULL Pointer Dereference</a>
Publication date: Tue, 07 Jun 2016 19:06:00 +0000