CVE-2017-15588
published 2017-10-18CVE-2017-15588: An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause…
PriorityP339high7.8CVSS 3.0
AVLACHPRLUINSCCHIHAH
EPSS
0.33%
25.1th percentile
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.2+xsa245-0+deb9u1 (bookworm) | xen 4.8.2+xsa245-0+deb9u1 (bookworm) |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.8.2+xsa245-0+deb9u1 | 4.8.2+xsa245-0+deb9u1 |
| xen | xen | >= 0 < 4.8.2+xsa245-0+deb9u1 | 4.8.2+xsa245-0+deb9u1 |
| xen | xen | >= 0 < 4.8.2+xsa245-0+deb9u1 | 4.8.2+xsa245-0+deb9u1 |
| xen | xen | >= 0 < 4.8.2+xsa245-0+deb9u1 | 4.8.2+xsa245-0+deb9u1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: Stale TLB entry due to page type release race (XSA-241)
vendor_redhat·2017-10-12·CVSS 7.8
CVE-2017-15588 [HIGH] xen: Stale TLB entry due to page type release race (XSA-241)
xen: Stale TLB entry due to page type release race (XSA-241)
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-15588: xen - An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to e...
vendor_debian·2017·CVSS 7.8
CVE-2017-15588 [HIGH] CVE-2017-15588: xen - An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to e...
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
Scope: local
bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
bullseye: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
forky: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
sid: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
trixie: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
GHSA
GHSA-5chc-m6j7-c756: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-14
CVE-2017-15588 [HIGH] CWE-362 GHSA-5chc-m6j7-c756: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
Project0
Taking a page from the kernel's book: A TLB issue in mremap() - Project Zero
project_zero·2019-01-01·CVSS 7.0
CVE-2016-5195 [HIGH] Taking a page from the kernel's book: A TLB issue in mremap() - Project Zero
Posted by Jann Horn, Project Zero
This is a technical blog post about TLB flushing bugs in kernels, intended for people interested in kernel security and memory management.
Introduction: Bugs in Memory Management code
There have been some pretty scary bugs in memory management in the past, like:
-
CVE-2016-5195, a logic bug in the Linux kernel that permitted writing to shared read-only pages
-
CVE-2018-1038, a Windows bug that existed for about two months, where a bit was set incorrectly in a page table, permitting userspace to overwrite page tables
Memory management is one of the core functions that every kernel and hypervisor needs to implement; and the correctness of memory management code is very important to the security of the entire system. I hope that this post encourages
OSV
CVE-2017-15588: An issue was discovered in Xen through 4
osv·2017-10-18·CVSS 7.8
CVE-2017-15588 [HIGH] CVE-2017-15588: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15588 CVE-2017-15589 CVE-2017-15590 CVE-2017-15591 CVE-2017-15592 CVE-2017-15593 CVE-2017-15594 CVE-2017-15595 xen: various flaws [fedora-all]
bugzilla·2017-10-12·CVSS 7.8
CVE-2017-15588 [HIGH] CVE-2017-15588 CVE-2017-15589 CVE-2017-15590 CVE-2017-15591 CVE-2017-15592 CVE-2017-15593 CVE-2017-15594 CVE-2017-15595 xen: various flaws [fedora-all]
CVE-2017-15588 CVE-2017-15589 CVE-2017-15590 CVE-2017-15591 CVE-2017-15592 CVE-2017-15593 CVE-2017-15594 CVE-2017-15595 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fe
Bugzilla
CVE-2017-15588 xsa241 xen: Stale TLB entry due to page type release race (XSA-241)
bugzilla·2017-10-09·CVSS 7.8
CVE-2017-15588 [HIGH] CVE-2017-15588 xsa241 xen: Stale TLB entry due to page type release race (XSA-241)
CVE-2017-15588 xsa241 xen: Stale TLB entry due to page type release race (XSA-241)
ISSUE DESCRIPTION
x86 PV guests effect TLB flushes by way of a hypercall. Xen tries to
reduce the number of TLB flushes by delaying them as much as possible.
When the last type reference of a page is dropped, the need for a TLB
flush (before the page is re-used) is recorded. If a guest TLB flush
request involves an Inter Processor Interrupt (IPI) to a CPU in which
is the process of dropping the last type reference of some page, and
if that IPI arrives at exactly the right instruction boundary, a stale
time stamp may be recorded, possibly resulting in the later omission
of the necessary TLB flush for that page.
IMPACT
A malicious x86 PV guest may be able to access all of system memory,
allowing for all of
http://www.securityfocus.com/bid/101490http://www.securitytracker.com/id/1039568https://lists.debian.org/debian-lts-announce/2017/11/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2018/10/msg00009.htmlhttps://security.gentoo.org/glsa/201801-14https://support.citrix.com/article/CTX228867https://www.debian.org/security/2017/dsa-4050https://xenbits.xen.org/xsa/advisory-241.htmlhttp://www.securityfocus.com/bid/101490http://www.securitytracker.com/id/1039568https://lists.debian.org/debian-lts-announce/2017/11/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2018/10/msg00009.htmlhttps://security.gentoo.org/glsa/201801-14https://support.citrix.com/article/CTX228867https://www.debian.org/security/2017/dsa-4050https://xenbits.xen.org/xsa/advisory-241.html
2017-10-18
Published