PT-2017-13385 · Xen+1 · Xen+1

Eric Chanudet

·

Publicado

2017-09-12

·

Atualizado

2018-10-19

·

CVE-2017-14317

CVSS v3.1

5.6

Média

VetorAV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.10
Description A domain cleanup issue was discovered in the C xenstore daemon, which can cause a double-free when shutting down a VM with a stubdomain, resulting in a crash of the xenstored daemon. This can lead to a denial of service of any parts of the system relying on it, including domain creation and destruction, ballooning, and device changes.
Recommendations For versions prior to 4.10, update to a version 4.10 or later to resolve the issue.

Correção

DoS

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14317
DLA-1132-1
DLA-1549-1
DSA-4050-1
OPENSUSE-SU-2017_2514-1
OPENSUSE-SU-2017_2540-1
SUSE-SU-2017:2420-1
SUSE-SU-2017:2450-1
SUSE-SU-2017:2466-1
SUSE-SU-2017:2519-1
SUSE-SU-2017:2541-1
SUSE-SU-2017:2611-1

Produtos afetados

Suse
Xen