cbcvebase.
CVE-2017-12134
published 2017-08-24

CVE-2017-12134: The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently…

high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.

Affected

20 ranges
VendorProductVersion rangeFixed in
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debianlinux< linux 4.12.12-1 (bookworm)linux 4.12.12-1 (bookworm)
linuxlinux_kernel>= 0 < 4.12.12-14.12.12-1
linuxlinux_kernel>= 0 < 4.12.12-14.12.12-1
linuxlinux_kernel>= 0 < 4.12.12-14.12.12-1
linuxlinux_kernel>= 0 < 4.12.12-14.12.12-1
linuxlinux_kernel>= 0 < 3.13.0-149.1993.13.0-149.199
linuxlinux_kernel>= 0 < 4.4.0-97.1204.4.0-97.120

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
osv8.8HIGH