UBUNTU-CVE-2017-15597
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-15597
Summary:
Details: An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.
References: https://ubuntu.com/security/CVE-2017-15597, https://xenbits.xen.org/xsa/advisory-236.html, https://www.cve.org/CVERecord?id=CVE-2017-15597
Affected packages
Package
Name: xen
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
