CVE-2017-10923
published 2017-07-05CVE-2017-10923: Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash)…
PriorityP429medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.80%
76.1th percentile
Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.1-1+deb9u3 (bookworm) | xen 4.8.1-1+deb9u3 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: arm: vgic: Out-of-bound access when sending SGIs (XSA-225)
vendor_redhat·2017-06-20·CVSS 6.5
CVE-2017-10923 [MEDIUM] xen: arm: vgic: Out-of-bound access when sending SGIs (XSA-225)
xen: arm: vgic: Out-of-bound access when sending SGIs (XSA-225)
Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
Mitigation: On systems where the guest kernel is controlled by the host rather than
guest administrator, running only kernels which only send sane IPIs
(i.e. targeting valid CPUs) will prevent untrusted guest users from
exploiting this issue. However untrusted guest administrators can
still trigger it unless further steps are taken to prevent them from
loading code into the kernel (e.g by disabling loadable modules etc) or
from using other mechanisms which allow them to run code at kernel
privilege.
Package: xen (Red Hat Enterprise Linux 5) - Not affecte
Debian
CVE-2017-10923: xen - Xen through 4.8.x does not validate a vCPU array index upon the sending of an SG...
vendor_debian·2017·CVSS 6.5
CVE-2017-10923 [MEDIUM] CVE-2017-10923: xen - Xen through 4.8.x does not validate a vCPU array index upon the sending of an SG...
Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: resolved (fixed in 4.8.1-1+deb9u3)
GHSA
GHSA-83mw-xpgw-63qr: Xen through 4
ghsa_unreviewed·2022-05-17
CVE-2017-10923 [MEDIUM] CWE-20 GHSA-83mw-xpgw-63qr: Xen through 4
Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
OSV
CVE-2017-10923: Xen through 4
osv·2017-07-05·CVSS 6.5
CVE-2017-10923 [MEDIUM] CVE-2017-10923: Xen through 4
Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
bugzilla·2017-06-20·CVSS 6.5
CVE-2017-10911 [MEDIUM] CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [
CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10918 CVE-2017-10919 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-10923 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also men
Bugzilla
CVE-2017-10923 xsa225 xen: arm: vgic: Out-of-bound access when sending SGIs (XSA-225)
bugzilla·2017-06-07·CVSS 6.5
CVE-2017-10923 [MEDIUM] CVE-2017-10923 xsa225 xen: arm: vgic: Out-of-bound access when sending SGIs (XSA-225)
CVE-2017-10923 xsa225 xen: arm: vgic: Out-of-bound access when sending SGIs (XSA-225)
ISSUE DESCRIPTION
ARM guests can send SGI (i.e. IPI) targeting a list of vCPUs using the
MMIO register GICD_SGIR (GICv2) or System Register ICC_SGI1R (GICv3).
However, the emulation code does not sanitize the list and will
directly access an array without checking whether the array index is
within bounds.
IMPACT
A guest may cause a hypervisor crash, resulting in a Denial of Service
(DoS).
VULNERABLE SYSTEMS
Xen versions 4.6 and onwards are affected. Xen versions 4.5 and
earlier are not affected.
Only ARM systems are affected. x86 systems are not affected.
Mitigation:
On systems where the guest kernel is controlled by the host rather than
guest administrator, running only kernels which only send s
http://www.securityfocus.com/bid/99160http://www.securitytracker.com/id/1038735https://security.gentoo.org/glsa/201708-03https://xenbits.xen.org/xsa/advisory-225.htmlhttp://www.securityfocus.com/bid/99160http://www.securitytracker.com/id/1038735https://security.gentoo.org/glsa/201708-03https://xenbits.xen.org/xsa/advisory-225.html
2017-07-05
Published