CVE-2017-15597
published 2017-10-30CVE-2017-15597: An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference…
PriorityP342critical9.1CVSS 3.0
AVNACLPRHUINSCCHIHAH
EPSS
2.81%
85.0th percentile
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.2+xsa245-0+deb9u1 (bookworm) | xen 4.8.2+xsa245-0+deb9u1 (bookworm) |
| xen | xen | <= 4.9.0 | — |
| xen | xen | >= 0 < 4.8.2+xsa245-0+deb9u1 | 4.8.2+xsa245-0+deb9u1 |
| xen | xen | >= 0 < 4.8.2+xsa245-0+deb9u1 | 4.8.2+xsa245-0+deb9u1 |
| xen | xen | >= 0 < 4.8.2+xsa245-0+deb9u1 | 4.8.2+xsa245-0+deb9u1 |
| xen | xen | >= 0 < 4.8.2+xsa245-0+deb9u1 | 4.8.2+xsa245-0+deb9u1 |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-53jp-4hq4-cmc7: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-13
CVE-2017-15597 [CRITICAL] CWE-119 GHSA-53jp-4hq4-cmc7: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.
OSV
CVE-2017-15597: An issue was discovered in Xen through 4
osv·2017-10-30·CVSS 9.1
CVE-2017-15597 [CRITICAL] CVE-2017-15597: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.
Red Hat
xen: pin count / page reference race in grant table code (XSA-236)
vendor_redhat·2017-10-24·CVSS 9.1
CVE-2017-15597 [CRITICAL] xen: pin count / page reference race in grant table code (XSA-236)
xen: pin count / page reference race in grant table code (XSA-236)
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-15597: xen - An issue was discovered in Xen through 4.9.x. Grant copying code made an implica...
vendor_debian·2017·CVSS 9.1
CVE-2017-15597 [CRITICAL] CVE-2017-15597: xen - An issue was discovered in Xen through 4.9.x. Grant copying code made an implica...
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.
Scope: local
bookworm: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
bullseye: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
forky: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
sid: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
trixie: resolved (fixed in 4.8.2+xsa245-0+deb9u1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15597 xen: xsa236 xen: pin count / page reference race in grant table code (XSA-236) [fedora-all]
bugzilla·2017-10-26·CVSS 9.1
CVE-2017-15597 [CRITICAL] CVE-2017-15597 xen: xsa236 xen: pin count / page reference race in grant table code (XSA-236) [fedora-all]
CVE-2017-15597 xen: xsa236 xen: pin count / page reference race in grant table code (XSA-236) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2017-15597 xsa236 xen: pin count / page reference race in grant table code (XSA-236)
bugzilla·2017-10-09·CVSS 9.1
CVE-2017-15597 [CRITICAL] CVE-2017-15597 xsa236 xen: pin count / page reference race in grant table code (XSA-236)
CVE-2017-15597 xsa236 xen: pin count / page reference race in grant table code (XSA-236)
ISSUE DESCRIPTION
Grant copying code made an implication that any grant pin would be
accompanied by a suitable page reference. Other portions of code,
however, did not match up with that assumption. When such a grant
copy operation is being done on a grant of a dying domain, the
assumption turns out wrong.
IMPACT
A malicious guest administrator can cause can cause hypervisor memory
corruption, most likely resulting in host crash and a Denial of
Service. Privilege escalation and information leaks cannot be ruled
out.
VULNERABLE SYSTEMS
Xen versions from 4.2 onwards are vulnerable. Xen versions 4.1 and
earlier are not vulnerable.
Both x86 and ARM are vulnerable, and on x86 both PV and HVM guests c
http://www.openwall.com/lists/oss-security/2017/10/24/3http://www.securityfocus.com/bid/101564http://www.securitytracker.com/id/1039653http://xenbits.xen.org/xsa/advisory-236.htmlhttps://lists.debian.org/debian-lts-announce/2018/10/msg00009.htmlhttps://support.citrix.com/article/CTX229057https://www.debian.org/security/2017/dsa-4050http://www.openwall.com/lists/oss-security/2017/10/24/3http://www.securityfocus.com/bid/101564http://www.securitytracker.com/id/1039653http://xenbits.xen.org/xsa/advisory-236.htmlhttps://lists.debian.org/debian-lts-announce/2018/10/msg00009.htmlhttps://support.citrix.com/article/CTX229057https://www.debian.org/security/2017/dsa-4050
2017-10-30
Published