Race condition in Xen - CVE-2017-14317
Published: September 14, 2017
Vulnerability identifier: #VU8426
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14317
CWE-ID: CWE-362
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an adjacent attacker to cause DoS condition on the host system.
The weakness exists due to race condition in cxenstored. An adjacent attacker can shut down a virtual machine with a stubdomain, trigger a double-free memory error and cause the xenstored daemon to crash.
The vulnerability is exploitable on the systems running the C version os xenstored ("xenstored") and running devicemodel stubdomains.
The weakness exists due to race condition in cxenstored. An adjacent attacker can shut down a virtual machine with a stubdomain, trigger a double-free memory error and cause the xenstored daemon to crash.
The vulnerability is exploitable on the systems running the C version os xenstored ("xenstored") and running devicemodel stubdomains.
Affected software
Xen
Debian Linux
SUSE Linux
Fedora
xen (Alpine package)
xen
Debian Linux
SUSE Linux
Fedora
xen (Alpine package)
xen
How to mitigate CVE-2017-14317
Install update from vendor's website.
xen (Alpine package) - addressed in versions 4.6.3-r9, 4.6.3-r11
xen - addressed in versions 4.7.3-5.fc25, 4.8.2-2.fc26, 4.9.0-10.fc27
xen - addressed in versions 4.7.3-5.fc25, 4.8.2-2.fc26, 4.9.0-10.fc27
External References
Related Security Bulletins
- Multiple vulnerabilities in Xen
- SUSE Linux update for xen
- Debian update for xen
- OpenSUSE Linux update for xen
- OpenSUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- Race condition in xen (Alpine package)
- Fedora 27 update for xen
- Fedora 26 update for xen
- Fedora 25 update for xen