Impact
The libfsimage iso9660 driver in Xen derives lengths from on‑disk fields without validation, allowing an integer underflow when calculating the System Use area. The unchecked underflow can lead to out‑of‑bounds memory corruption that may enable an attacker to read or write arbitrary memory, potentially leading to code execution or a host crash. This weakness is an integer underflow (CWE‑191).
Affected Systems
The vulnerability affects the Xen hypervisor component that processes ISO9660 filesystems. All Xen releases prior to the fix in the XSA‑497 advisory are at risk; the CVE does not list specific version numbers.
Risk and Exploitability
The CVSS score of 5.5 places the vulnerability in the medium severity range, and the EPSS < 1% indicates that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to present a crafted ISO9660 filesystem to a Xen host that parses it, such as through a guest boot disk or shared storage. The advisory provides a workaround that runs pygrub in a de‑privileged mode, which mitigates the issue; alternatively disabling pygrub or using pvgrub is advised. In the absence of a patch the risk remains moderate but could be leveraged to compromise the host if the hypervisor processes an attacker‑controlled volume.
OpenCVE Enrichment
Debian DSA