Privilege escalation in Xen - CVE-2017-12855

 

Privilege escalation in Xen - CVE-2017-12855

Published: August 16, 2017


Vulnerability identifier: #VU7953
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12855
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker on the guest system to gain elevated privileges on the host system.

The weakness exists due to flaws when clearing grant status bits. A local attacker on a guest system may modify or reuse a grant that is still in use by another domain and obtain potentially sensitive information from another guest on the target system.


a flaw when clearing grant status bits prematurely. As a result, a guest system may modify or reuse a grant that is still in use by another domain. A local attacker on a guest system may modify or reuse a grant that is still in use by another domain and obtain potentially sensitive information from another guest on the target system.

Affected software

Xen
xen (Alpine package)

How to mitigate CVE-2017-12855

Install update from vendor's website.

xen (Alpine package) - update to 4.6.6-r0

External References

Related Security Bulletins