Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10915

Опубликовано: 20 июн. 2017
Источник: redhat
CVSS3: 8.5
EPSS Низкий

Описание

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

Меры по смягчению последствий

Where the HVM guest is explicitly configured to use shadow paging (eg via the hap=0' xl domain configuration file parameter), changing to HAP (eg by setting hap=1') will avoid exposing the vulnerability to those guests. HAP is the default (in upstream Xen), where the hardware supports it; so this mitigation is only applicable if HAP has been disabled by configuration. (This mitigation is not applicable to PV guests.)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xenWill not fix

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1458873xen: x86: insufficient reference counts during shadow emulation (XSA-219)

EPSS

Процентиль: 65%
0.00492
Низкий

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 9
ubuntu
больше 8 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

CVSS3: 9
nvd
больше 8 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

CVSS3: 9
debian
больше 8 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page referen ...

CVSS3: 9
github
больше 3 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

suse-cvrf
больше 8 лет назад

Security update for xen

EPSS

Процентиль: 65%
0.00492
Низкий

8.5 High

CVSS3