CVE-2017-10915
published 2017-07-05CVE-2017-10915: The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain…
PriorityP343critical9CVSS 3.0
AVNACHPRNUINSCCHIHAH
EPSS
1.67%
74.2th percentile
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.1-1+deb9u3 (bookworm) | xen 4.8.1-1+deb9u3 (bookworm) |
| xen | xen | <= 4.8.1 | — |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
CVSS provenance
nvdv3.09.0CRITICALCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.0CRITICAL
vendor_debian9.0CRITICAL
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j89r-h362-8fxj: The shadow-paging feature in Xen through 4
ghsa_unreviewed·2022-05-17
CVE-2017-10915 [CRITICAL] CWE-362 GHSA-j89r-h362-8fxj: The shadow-paging feature in Xen through 4
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
OSV
CVE-2017-10915: The shadow-paging feature in Xen through 4
osv·2017-07-05·CVSS 9.0
CVE-2017-10915 [CRITICAL] CVE-2017-10915: The shadow-paging feature in Xen through 4
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
Red Hat
xen: x86: insufficient reference counts during shadow emulation (XSA-219)
vendor_redhat·2017-06-20·CVSS 9.0
CVE-2017-10915 [CRITICAL] xen: x86: insufficient reference counts during shadow emulation (XSA-219)
xen: x86: insufficient reference counts during shadow emulation (XSA-219)
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
Mitigation: Where the HVM guest is explicitly configured to use shadow paging (eg
via the `hap=0' xl domain configuration file parameter), changing to
HAP (eg by setting `hap=1') will avoid exposing the vulnerability to
those guests. HAP is the default (in upstream Xen), where the
hardware supports it; so this mitigation is only applicable if HAP has
been disabled by configuration.
(This mitigation is not applicable to PV guests.)
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-10915: xen - The shadow-paging feature in Xen through 4.8.x mismanages page references and co...
vendor_debian·2017·CVSS 9.0
CVE-2017-10915 [CRITICAL] CVE-2017-10915: xen - The shadow-paging feature in Xen through 4.8.x mismanages page references and co...
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: resolved (fixed in 4.8.1-1+deb9u3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
bugzilla·2017-06-20·CVSS 6.5
CVE-2017-10911 [MEDIUM] CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also men
Bugzilla
CVE-2017-10915 xsa219 xen: x86: insufficient reference counts during shadow emulation (XSA-219)
bugzilla·2017-06-05·CVSS 9.0
CVE-2017-10915 [CRITICAL] CVE-2017-10915 xsa219 xen: x86: insufficient reference counts during shadow emulation (XSA-219)
CVE-2017-10915 xsa219 xen: x86: insufficient reference counts during shadow emulation (XSA-219)
ISSUE DESCRIPTION
When using shadow paging, writes to guest pagetables must be trapped and
emulated, so the shadows can be suitably adjusted as well.
When emulating the write, Xen maps the guests pagetable(s) to make the final
adjustment and leave the guest's view of its state consistent.
However, when mapping the frame, Xen drops the page reference before
performing the write. This is a race window where the underlying frame can
change ownership.
One possible attack scenario is for the frame to change ownership and to be
inserted into a PV guest's pagetables. At that point, the emulated write will
be an unaudited modification to the PV pagetables whose value is under guest
control.
IMPACT
http://www.debian.org/security/2017/dsa-3969http://www.securityfocus.com/bid/99174https://security.gentoo.org/glsa/201708-03https://security.gentoo.org/glsa/201710-17https://xenbits.xen.org/xsa/advisory-219.htmlhttp://www.debian.org/security/2017/dsa-3969http://www.securityfocus.com/bid/99174https://security.gentoo.org/glsa/201708-03https://security.gentoo.org/glsa/201710-17https://xenbits.xen.org/xsa/advisory-219.html
2017-07-05
Published