Xen · Xen · CVE-2018-10472
Name of the Vulnerable Software and Affected Versions:
Xen versions prior to 4.11
Description:
An issue allows x86 HVM guest OS users to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
Recommendations:
For versions prior to 4.11, update to version 4.11 or later to resolve the issue.