CVE-2017-12855
published 2017-08-15CVE-2017-12855: Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details…
PriorityP426medium6.5CVSS 3.0
AVLACLPRLUINSCCHINAN
EPSS
0.40%
32.1th percentile
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.1-1+deb9u3 (bookworm) | xen 4.8.1-1+deb9u3 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
| xen | xen | >= 0 < 4.8.1-1+deb9u3 | 4.8.1-1+deb9u3 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c6pm-8crm-3rr8: Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use
ghsa_unreviewed·2022-05-17
CVE-2017-12855 [MEDIUM] CWE-200 GHSA-c6pm-8crm-3rr8: Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected.
OSV
CVE-2017-12855: Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use
osv·2017-08-15·CVSS 6.5
CVE-2017-12855 [MEDIUM] CVE-2017-12855: Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected.
Red Hat
xen: grant_table: possibly premature clearing of GTF_writing / GTF_reading (XSA-230)
vendor_redhat·2017-08-15·CVSS 6.5
CVE-2017-12855 [MEDIUM] xen: grant_table: possibly premature clearing of GTF_writing / GTF_reading (XSA-230)
xen: grant_table: possibly premature clearing of GTF_writing / GTF_reading (XSA-230)
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-12855: xen - Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest t...
vendor_debian·2017·CVSS 6.5
CVE-2017-12855 [MEDIUM] CVE-2017-12855: xen - Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest t...
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected.
Scope: local
bookworm: resolved (fixed in 4.8.1-1+deb9u3)
bullseye: resolved (fixed in 4.8.1-1+deb9u3)
forky: resolved (fixed in 4.8.1-1+deb9u3)
sid: res
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12855 xsa230 CVE-2017-12855 xen: grant_table: possibly premature clearing of GTF_writing / GTF_reading (XSA-230)
bugzilla·2017-08-15·CVSS 6.5
CVE-2017-12855 [MEDIUM] CVE-2017-12855 xsa230 CVE-2017-12855 xen: grant_table: possibly premature clearing of GTF_writing / GTF_reading (XSA-230)
CVE-2017-12855 xsa230 CVE-2017-12855 xen: grant_table: possibly premature clearing of GTF_writing / GTF_reading (XSA-230)
ISSUE DESCRIPTION
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the
guest that a grant is in use. A guest is expected not to modify the
grant details while it is in use, whereas the guest is free to
modify/reuse the grant entry when it is not in use.
Under some circumstances, Xen will clear the status bits too early,
incorrectly informing the guest that the grant is no longer in use.
IMPACT
A guest may prematurely believe that a granted frame is safely private
again, and reuse it in a way which contains sensitive information, while
the domain on the far end of the grant is still using the grant.
VULNERABLE SYSTEMS
All systems are vulnerable
Bugzilla
CVE-2017-12134 CVE-2017-12135 CVE-2017-12136 CVE-2017-12137 CVE-2017-12855 xen: various flaws [fedora-all]
bugzilla·2017-08-15·CVSS 8.8
CVE-2017-12134 [HIGH] CVE-2017-12134 CVE-2017-12135 CVE-2017-12136 CVE-2017-12137 CVE-2017-12855 xen: various flaws [fedora-all]
CVE-2017-12134 CVE-2017-12135 CVE-2017-12136 CVE-2017-12137 CVE-2017-12855 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
http://www.debian.org/security/2017/dsa-3969http://www.securityfocus.com/bid/100341http://www.securitytracker.com/id/1039177http://xenbits.xen.org/xsa/advisory-230.htmlhttps://support.citrix.com/article/CTX225941http://www.debian.org/security/2017/dsa-3969http://www.securityfocus.com/bid/100341http://www.securitytracker.com/id/1039177http://xenbits.xen.org/xsa/advisory-230.htmlhttps://support.citrix.com/article/CTX225941
2017-08-15
Published