CVE Vulnerabilities

CVE-2017-17564

Published: Dec 12, 2017 | Modified: Oct 19, 2018
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging incorrect error handling for reference counting in shadow mode.

Affected Software

Name Vendor Start Version End Version
Xen Xen * 4.9.1 (including)
Xen Ubuntu artful *
Xen Ubuntu bionic *
Xen Ubuntu esm-infra/xenial *
Xen Ubuntu trusty *
Xen Ubuntu upstream *
Xen Ubuntu xenial *
Xen Ubuntu zesty *

References