PT-2017-2783 · Citrix+2 · Xen+3
Jan H. Schönherr
·
Published
2017-08-02
·
Updated
2019-10-03
·
CVE-2017-12134
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Xen (affected versions not specified)
XenServer (affected versions not specified)
Description
The issue is related to the
xen biovec phys mergeable function in the biomerge.c driver, which has inadequate access control to certain functions. This can be exploited by a local attacker to elevate privileges, damage block device data streams, breach confidentiality, and cause a denial of service by leveraging incorrect block IO merge-ability calculation.Recommendations
For Xen, consider restricting access to the
xen biovec phys mergeable function in the biomerge.c driver until a patch is available.
For XenServer, consider restricting access to the xen biovec phys mergeable function in the biomerge.c driver until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Ubuntu
Xen
Xenserver