Privilege escalation in Xen - CVE-2017-12137
Published: August 16, 2017
Vulnerability identifier: #VU7950
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2017-12137
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker on a PV guest system to gain elevated privileges on the host system.
The weakness exists due to a flaw in the processing of guest-nominated L1 pagetable entries when mapping a grant reference. A local attacker on a PV guest system supply specially crafted data and execute arbitrary code on the host system.
The weakness exists due to a flaw in the processing of guest-nominated L1 pagetable entries when mapping a grant reference. A local attacker on a PV guest system supply specially crafted data and execute arbitrary code on the host system.
Affected software
Xen
Gentoo Linux
xen (Alpine package)
Gentoo Linux
xen (Alpine package)
How to mitigate CVE-2017-12137
Install update from vendor's website.
xen (Alpine package) - update to 4.6.6-r0