Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10915

Опубликовано: 20 июн. 2017
Источник: redhat
CVSS3: 8.5

Описание

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

Меры по смягчению последствий

Where the HVM guest is explicitly configured to use shadow paging (eg via the hap=0' xl domain configuration file parameter), changing to HAP (eg by setting hap=1') will avoid exposing the vulnerability to those guests. HAP is the default (in upstream Xen), where the hardware supports it; so this mitigation is only applicable if HAP has been disabled by configuration. (This mitigation is not applicable to PV guests.)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xenWill not fix

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1458873xen: x86: insufficient reference counts during shadow emulation (XSA-219)

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 9
ubuntu
около 9 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

CVSS3: 9
nvd
около 9 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

CVSS3: 9
debian
около 9 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page referen ...

CVSS3: 9
github
больше 4 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

suse-cvrf
около 9 лет назад

Security update for xen

8.5 High

CVSS3