A new vulnerability in emulation code used by the Xen virtualization software can allow attackers to bypass the security barrier between virtual machines and the host operating systems they run on. The vulnerability is located in the CD-ROM drive emulation feature of QEMU, an open source hardware emulator that’s used by Xen, KVM and other virtualization platforms. The flaw is tracked as CVE-2015-5154 in the Common Vulnerabilities and Exposures database. Fortunately, Xen-based virtualization systems that are not configured to emulate a drive inside the guest OS are not affected.”]
Source: https://www.csoonline.com/article/2953525/xen-patches-new-virtualmachine-escape-vulnerability.html

