Privilege escalation in Xen - CVE-2017-12136

 

Privilege escalation in Xen - CVE-2017-12136

Published: August 16, 2017


Vulnerability identifier: #VU7951
CSH Severity: Low
CVSS v4: 6.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:H]
CVE-ID: CVE-2017-12136
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local administrative attacker on the guest system to gain elevated privileges on the host system.

The weakness exists due to a race condition in the grant table allocator maptrack entry list processing code. A local attacker on the guest system can cause the host system to crash or gain elevated privileges on the host system.

Affected software

Xen
Gentoo Linux
xen (Alpine package)

How to mitigate CVE-2017-12136

Install update from vendor's website.

xen (Alpine package) - update to 4.6.6-r0

External References

Related Security Bulletins