Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14319

Опубликовано: 12 сент. 2017
Источник: redhat
CVSS3: 8.8

Описание

A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xenWill not fix

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1486710xen: insufficient grant unmapping checks for x86 PV guests (XSA-234)

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.

CVSS3: 8.8
nvd
больше 8 лет назад

A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.

CVSS3: 8.8
debian
больше 8 лет назад

A grant unmapping issue was discovered in Xen through 4.9.x. When remo ...

CVSS3: 8.8
github
больше 3 лет назад

A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.

CVSS3: 8.8
fstec
больше 8 лет назад

Уязвимость гипервизора Xen, связанная с ошибками сопоставления прав доступа, позволяющая нарушителю повысить свои привилегии или вызвать отказ в обслуживании

8.8 High

CVSS3