Privilege escalation in Xen - CVE-2017-12136
Published: August 16, 2017
Vulnerability identifier: #VU7951
CSH Severity: Low
CVSS v4: 6.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:H]
CVE-ID: CVE-2017-12136
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local administrative attacker on the guest system to gain elevated privileges on the host system.
The weakness exists due to a race condition in the grant table allocator maptrack entry list processing code. A local attacker on the guest system can cause the host system to crash or gain elevated privileges on the host system.
The weakness exists due to a race condition in the grant table allocator maptrack entry list processing code. A local attacker on the guest system can cause the host system to crash or gain elevated privileges on the host system.
Affected software
Xen
Gentoo Linux
xen (Alpine package)
Gentoo Linux
xen (Alpine package)
How to mitigate CVE-2017-12136
Install update from vendor's website.
xen (Alpine package) - update to 4.6.6-r0