CVE-2017-10919
published 2017-07-05CVE-2017-10919: Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.
PriorityP430medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.90%
77.5th percentile
Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.1-1+deb9u3 (bookworm) | xen 4.8.1-1+deb9u3 (bookworm) |
| xen | xen | <= 4.8.1 | — |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rj6j-c835-5x5f: Xen through 4
ghsa_unreviewed·2022-05-13
CVE-2017-10919 [MEDIUM] GHSA-rj6j-c835-5x5f: Xen through 4
Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.
OSV
CVE-2017-10919: Xen through 4
osv·2017-07-05·CVSS 6.5
CVE-2017-10919 [MEDIUM] CVE-2017-10919: Xen through 4
Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.
Red Hat
xen: ARM guest disabling interrupt may crash Xen (XSA-223)
vendor_redhat·2017-06-20·CVSS 6.5
CVE-2017-10919 [MEDIUM] xen: ARM guest disabling interrupt may crash Xen (XSA-223)
xen: ARM guest disabling interrupt may crash Xen (XSA-223)
Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.
Mitigation: On systems where the guest kernel is controlled by the host rather than
guest administrator, running only kernels which do not disable SGI and
PPI (i.e IRQ < 32) will prevent untrusted guest users from exploiting
this issue. However untrusted guest administrators can still trigger it
unless further steps are taken to prevent them from loading code into
the kernel (e.g by disabling loadable modules etc) or from using other
mechanisms which allow them to run code at kernel privilege.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-10919: xen - Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS ...
vendor_debian·2017·CVSS 6.5
CVE-2017-10919 [MEDIUM] CVE-2017-10919: xen - Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS ...
Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: resolved (fixed in 4.8.1-1+deb9u3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
bugzilla·2017-06-20·CVSS 6.5
CVE-2017-10911 [MEDIUM] CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also men
Bugzilla
CVE-2017-10919 xsa223 xen: ARM guest disabling interrupt may crash Xen (XSA-223)
bugzilla·2017-06-05·CVSS 6.5
CVE-2017-10919 [MEDIUM] CVE-2017-10919 xsa223 xen: ARM guest disabling interrupt may crash Xen (XSA-223)
CVE-2017-10919 xsa223 xen: ARM guest disabling interrupt may crash Xen (XSA-223)
ISSUE DESCRIPTION
Virtual interrupt injection could be triggered by a guest when sending
an SGI (e.g IPI) to any vCPU or by configuring timers. When the virtual
interrupt is masked, a missing check in the injection path may result in
reading invalid hardware register or crashing the host.
IMPACT
A guest may cause a hypervisor crash, resulting in a Denial of Service
(DoS).
VULNERABLE SYSTEMS
All Xen versions which support ARM are affected.
x86 systems are not affected.
Mitigation:
On systems where the guest kernel is controlled by the host rather than
guest administrator, running only kernels which do not disable SGI and
PPI (i.e IRQ < 32) will prevent untrusted guest users from exploiting
this issue.
http://www.debian.org/security/2017/dsa-3969http://www.securityfocus.com/bid/99159http://www.securitytracker.com/id/1038733https://security.gentoo.org/glsa/201708-03https://xenbits.xen.org/xsa/advisory-223.htmlhttp://www.debian.org/security/2017/dsa-3969http://www.securityfocus.com/bid/99159http://www.securitytracker.com/id/1038733https://security.gentoo.org/glsa/201708-03https://xenbits.xen.org/xsa/advisory-223.html
2017-07-05
Published