PT-2017-2783 · Citrix+2 · Xen+3
Jan H. Schönherr
·
Publicado
2017-08-02
·
Atualizado
2019-10-03
·
CVE-2017-12134
CVSS v3.1
8.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xen (affected versions not specified)
XenServer (affected versions not specified)
Description
The issue is related to the
xen biovec phys mergeable function in the biomerge.c driver, which has inadequate access control to certain functions. This can be exploited by a local attacker to elevate privileges, damage block device data streams, breach confidentiality, and cause a denial of service by leveraging incorrect block IO merge-ability calculation.Recommendations
For Xen, consider restricting access to the
xen biovec phys mergeable function in the biomerge.c driver until a patch is available.
For XenServer, consider restricting access to the xen biovec phys mergeable function in the biomerge.c driver until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Suse
Ubuntu
Xen
Xenserver