PT-2017-11606 · Xen+1 · Xen+1

Andrew Cooper

·

Publicado

2017-07-05

·

Atualizado

2017-11-04

·

CVE-2017-10916

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.9
Description The issue arises from improper interaction between the vCPU context-switch implementation and the Memory Protection Extensions (MPX) and Protection Key (PKU) features in Xen. This interaction makes it easier for guest OS users to bypass Address Space Layout Randomization (ASLR) and other protection mechanisms.
Recommendations For Xen versions prior to 4.9, update to version 4.9 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-10916
DSA-3969-1
SUSE-SU-2017:1812-1

Produtos afetados

Suse
Xen