PT-2017-2369 · Xen+2 · Xen+2
Jann Horn
·
Published
2017-04-04
·
Updated
2019-10-03
·
CVE-2017-7228
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xen versions 4.4.x through 4.8.x
Description
The issue is related to inadequate access control in the Xen hypervisor. It allows a local attacker to access hypervisor memory outside of the guest-provided input/output arrays due to insufficient checking of XENMEM exchange input, which was introduced by the earlier XSA-29 fix.
Recommendations
For versions 4.4.x through 4.8.x, apply the available fixes to resolve the issue.
As a temporary workaround, consider restricting access to the XENMEM exchange input to minimize the risk of exploitation.
Exploit
Fix
Improper Validation of Array Index
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Xen