CVE-2017-12136
published 2017-08-24CVE-2017-12136: Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and…
PriorityP336high7.8CVSS 3.0
AVLACHPRLUINSCCHIHAH
EPSS
0.31%
23.4th percentile
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.8.1-1+deb9u3 (bookworm) | xen 4.8.1-1+deb9u3 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: grant_table: Race conditions with maptrack free list handling (XSA-228)
vendor_redhat·2017-08-15·CVSS 7.8
CVE-2017-12136 [HIGH] xen: grant_table: Race conditions with maptrack free list handling (XSA-228)
xen: grant_table: Race conditions with maptrack free list handling (XSA-228)
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2017-12136: xen - Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local g...
vendor_debian·2017·CVSS 7.8
CVE-2017-12136 [HIGH] CVE-2017-12136: xen - Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local g...
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: resolved (fixed in 4.8.1-1+deb9u3)
Citrix
Citrix Security Bulletin CTX225941
vendor_citrix·CVSS 8.8
CVE-2017-12134 [HIGH] Citrix Security Bulletin CTX225941
Citrix Security Bulletin CTX225941
CVE References: CVE-2017-12134, CVE-2017-12135, CVE-2017-12136, CVE-2017-12137, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-9r53-65fp-9gr6: Race condition in the grant table code in Xen 4
ghsa_unreviewed·2022-05-14
CVE-2017-12136 [HIGH] CWE-362 GHSA-9r53-65fp-9gr6: Race condition in the grant table code in Xen 4
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
OSV
CVE-2017-12136: Race condition in the grant table code in Xen 4
osv·2017-08-24·CVSS 7.8
CVE-2017-12136 [HIGH] CVE-2017-12136: Race condition in the grant table code in Xen 4
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12134 CVE-2017-12135 CVE-2017-12136 CVE-2017-12137 CVE-2017-12855 xen: various flaws [fedora-all]
bugzilla·2017-08-15·CVSS 8.8
CVE-2017-12134 [HIGH] CVE-2017-12134 CVE-2017-12135 CVE-2017-12136 CVE-2017-12137 CVE-2017-12855 xen: various flaws [fedora-all]
CVE-2017-12134 CVE-2017-12135 CVE-2017-12136 CVE-2017-12137 CVE-2017-12855 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2017-12136 xsa228 xen: grant_table: Race conditions with maptrack free list handling (XSA-228)
bugzilla·2017-08-02·CVSS 7.8
CVE-2017-12136 [HIGH] CVE-2017-12136 xsa228 xen: grant_table: Race conditions with maptrack free list handling (XSA-228)
CVE-2017-12136 xsa228 xen: grant_table: Race conditions with maptrack free list handling (XSA-228)
ISSUE DESCRIPTION
The grant table code in Xen has a bespoke semi-lockfree allocator for
recording grant mappings ("maptrack" entries). This allocator has a
race which allows the free list to be corrupted.
Specifically: the code for removing an entry from the free list, prior
to use, assumes (without locking) that if inspecting head item shows
that it is not the tail, it will continue to not be the tail of the
list if it is later found to be still the head and removed with
cmpxchg. But the entry might have been removed and replaced, with the
result that it might be the tail by then. (The invariants for the
semi-lockfree data structure were never formally documented.)
Additionally, a stolen
http://www.debian.org/security/2017/dsa-3969http://www.openwall.com/lists/oss-security/2017/08/15/3http://www.securityfocus.com/bid/100346http://www.securitytracker.com/id/1039175http://xenbits.xen.org/xsa/advisory-228.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1477651https://security.gentoo.org/glsa/201801-14https://support.citrix.com/article/CTX225941http://www.debian.org/security/2017/dsa-3969http://www.openwall.com/lists/oss-security/2017/08/15/3http://www.securityfocus.com/bid/100346http://www.securitytracker.com/id/1039175http://xenbits.xen.org/xsa/advisory-228.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1477651https://security.gentoo.org/glsa/201801-14https://support.citrix.com/article/CTX225941
2017-08-24
Published