CVE-2017-10916
published 2017-07-05CVE-2017-10916: The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.35%
68.3th percentile
The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.1-1+deb9u3 (bookworm) | xen 4.8.1-1+deb9u3 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vrf7-6p2g-pr3x: The vCPU context-switch implementation in Xen through 4
ghsa_unreviewed·2022-05-17
CVE-2017-10916 [HIGH] CWE-200 GHSA-vrf7-6p2g-pr3x: The vCPU context-switch implementation in Xen through 4
The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.
OSV
CVE-2017-10916: The vCPU context-switch implementation in Xen through 4
osv·2017-07-05·CVSS 7.5
CVE-2017-10916 [HIGH] CVE-2017-10916: The vCPU context-switch implementation in Xen through 4
The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.
Red Hat
xen: x86: PKRU and BND* leakage between vCPU-s (XSA-220)
vendor_redhat·2017-06-20·CVSS 7.5
CVE-2017-10916 [HIGH] xen: x86: PKRU and BND* leakage between vCPU-s (XSA-220)
xen: x86: PKRU and BND* leakage between vCPU-s (XSA-220)
The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2017-10916: xen - The vCPU context-switch implementation in Xen through 4.8.x improperly interacts...
vendor_debian·2017·CVSS 7.5
CVE-2017-10916 [HIGH] CVE-2017-10916: xen - The vCPU context-switch implementation in Xen through 4.8.x improperly interacts...
The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: resolved (fixed in 4.8.1-1+deb9u3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
bugzilla·2017-06-20·CVSS 6.5
CVE-2017-10911 [MEDIUM] CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also men
Bugzilla
CVE-2017-10916 xsa220 xen: x86: PKRU and BND* leakage between vCPU-s (XSA-220)
bugzilla·2017-06-05·CVSS 7.5
CVE-2017-10916 [HIGH] CVE-2017-10916 xsa220 xen: x86: PKRU and BND* leakage between vCPU-s (XSA-220)
CVE-2017-10916 xsa220 xen: x86: PKRU and BND* leakage between vCPU-s (XSA-220)
ISSUE DESCRIPTION
Memory Protection Extensions (MPX) and Protection Key (PKU) are features in
newer processors, whose state is intended to be per-thread and context
switched along with all other XSAVE state.
Xen's vCPU context switch code would save and restore the state only
if the guest had set the relevant XSTATE enable bits. However,
surprisingly, the use of these features is not dependent (PKU) or may
not be dependent (MPX) on having the relevant XSTATE bits enabled.
VMs which use MPX or PKU, and context switch the state manually rather
than via XSAVE, will have the state leak between vCPUs (possibly,
between vCPUs in different guests). This in turn corrupts state in
the destination vCPU, and hence may
http://www.debian.org/security/2017/dsa-3969http://www.securityfocus.com/bid/99167http://www.securitytracker.com/id/1038730https://security.gentoo.org/glsa/201708-03https://xenbits.xen.org/xsa/advisory-220.htmlhttp://www.debian.org/security/2017/dsa-3969http://www.securityfocus.com/bid/99167http://www.securitytracker.com/id/1038730https://security.gentoo.org/glsa/201708-03https://xenbits.xen.org/xsa/advisory-220.html
2017-07-05
Published