CVE-2017-17566XEN vulnerability

7 documents6 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 71.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 12
Latest updateMay 13

Description

An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) or gain host OS privileges in shadow mode by mapping a certain auxiliary page.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.1 | Impact: 6.0

Affected Packages3 packages

debiandebian/xen< xen 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5 (bookworm)
Debianxen/xen< 4.8.3+comet2+shim4.10.0+comet3-1+deb9u5+3
NVDxen/xen4.9.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f7fj-gg64-5639: An issue was discovered in Xen through 42022-05-13
OSV
CVE-2017-17566: An issue was discovered in Xen through 42017-12-12

📋Vendor Advisories

2
Red Hat
xen: x86 PV guests may gain access to internally used pages (XSA-248)2017-12-12
Debian
CVE-2017-17566: xen - An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause...2017

💬Community

2
Bugzilla
CVE-2017-17563 CVE-2017-17564 CVE-2017-17565 CVE-2017-17566 xen: various flaws [fedora-all]2017-12-12
Bugzilla
CVE-2017-17566 xsa248 xen: x86 PV guests may gain access to internally used pages (XSA-248)2017-11-29