CVE-2017-12137
published 2017-08-24CVE-2017-12137: arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
PriorityP341high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.44%
35.4th percentile
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.8.1-1+deb9u3 (bookworm) | xen 4.8.1-1+deb9u3 (bookworm) |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fgc8-vw2h-qfxj: arch/x86/mm
ghsa_unreviewed·2022-05-13
CVE-2017-12137 [HIGH] CWE-120 GHSA-fgc8-vw2h-qfxj: arch/x86/mm
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
OSV
CVE-2017-12137: arch/x86/mm
osv·2017-08-24·CVSS 8.8
CVE-2017-12137 [HIGH] CVE-2017-12137: arch/x86/mm
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
Red Hat
xen: x86: PV privilege escalation via map_grant_ref (XSA-227)
vendor_redhat·2017-08-15·CVSS 8.8
CVE-2017-12137 [HIGH] xen: x86: PV privilege escalation via map_grant_ref (XSA-227)
xen: x86: PV privilege escalation via map_grant_ref (XSA-227)
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-12137: xen - arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges v...
vendor_debian·2017·CVSS 8.8
CVE-2017-12137 [HIGH] CVE-2017-12137: xen - arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges v...
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: resolved (fixed in 4.8.1-1+deb9u3)
trixie: resolved (fixed in 4.8.1-1+deb9u3)
Citrix
Citrix Security Bulletin CTX225941
vendor_citrix·CVSS 8.8
CVE-2017-12134 [HIGH] Citrix Security Bulletin CTX225941
Citrix Security Bulletin CTX225941
CVE References: CVE-2017-12134, CVE-2017-12135, CVE-2017-12136, CVE-2017-12137, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12134 CVE-2017-12135 CVE-2017-12136 CVE-2017-12137 CVE-2017-12855 xen: various flaws [fedora-all]
bugzilla·2017-08-15·CVSS 8.8
CVE-2017-12134 [HIGH] CVE-2017-12134 CVE-2017-12135 CVE-2017-12136 CVE-2017-12137 CVE-2017-12855 xen: various flaws [fedora-all]
CVE-2017-12134 CVE-2017-12135 CVE-2017-12136 CVE-2017-12137 CVE-2017-12855 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2017-12137 xsa227 xen: x86: PV privilege escalation via map_grant_ref (XSA-227)
bugzilla·2017-08-02·CVSS 8.8
CVE-2017-12137 [HIGH] CVE-2017-12137 xsa227 xen: x86: PV privilege escalation via map_grant_ref (XSA-227)
CVE-2017-12137 xsa227 xen: x86: PV privilege escalation via map_grant_ref (XSA-227)
ISSUE DESCRIPTION
When mapping a grant reference, a guest must inform Xen of where it
would like the grant mapped. For PV guests, this is done by nominating
an existing linear address, or an L1 pagetable entry, to be altered.
Neither of these PV paths check for alignment of the passed parameter.
The linear address path suitably truncates the linear address when
calculating the L1 entry to use, but the path which uses a directly
nominated L1 entry performs no checks.
This causes Xen to make an incorrectly-aligned update to a pagetable,
which corrupts both the intended entry and the subsequent entry with
values which are largely guest controlled. If the misaligned value
crosses a page boundary, then an ar
http://www.debian.org/security/2017/dsa-3969http://www.openwall.com/lists/oss-security/2017/08/15/2http://www.securityfocus.com/bid/100342http://www.securitytracker.com/id/1039174http://xenbits.xen.org/xsa/advisory-227.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1477657https://security.gentoo.org/glsa/201801-14https://support.citrix.com/article/CTX225941http://www.debian.org/security/2017/dsa-3969http://www.openwall.com/lists/oss-security/2017/08/15/2http://www.securityfocus.com/bid/100342http://www.securitytracker.com/id/1039174http://xenbits.xen.org/xsa/advisory-227.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1477657https://security.gentoo.org/glsa/201801-14https://support.citrix.com/article/CTX225941
2017-08-24
Published