Race condition in Xen - CVE-2017-14317

 

Race condition in Xen - CVE-2017-14317

Published: September 14, 2017


Vulnerability identifier: #VU8426
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14317
CWE-ID: CWE-362
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to cause DoS condition on the host system.

The weakness exists due to race condition in cxenstored. An adjacent attacker can shut down a virtual machine with a stubdomain, trigger a double-free memory error and cause the xenstored daemon to crash.

The vulnerability is exploitable on the systems running the C version os xenstored ("xenstored") and running devicemodel stubdomains.

Affected software

Xen
Debian Linux
SUSE Linux
Fedora
xen (Alpine package)
xen

How to mitigate CVE-2017-14317

Install update from vendor's website.

xen (Alpine package) - addressed in versions 4.6.3-r9, 4.6.3-r11
xen - addressed in versions 4.7.3-5.fc25, 4.8.2-2.fc26, 4.9.0-10.fc27

External References

Related Security Bulletins