PT-2017-11606 · Xen+1 · Xen+1

Andrew Cooper

·

Published

2017-07-05

·

Updated

2017-11-04

·

CVE-2017-10916

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.9
Description The issue arises from improper interaction between the vCPU context-switch implementation and the Memory Protection Extensions (MPX) and Protection Key (PKU) features in Xen. This interaction makes it easier for guest OS users to bypass Address Space Layout Randomization (ASLR) and other protection mechanisms.
Recommendations For Xen versions prior to 4.9, update to version 4.9 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10916
DSA-3969-1
SUSE-SU-2017:1812-1

Affected Products

Suse
Xen