Race condition in Xen - CVE-2017-15597

 

Race condition in Xen - CVE-2017-15597

Published: October 25, 2017


Vulnerability identifier: #VU8923
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15597
CWE-ID: CWE-362
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent administrative attacker to cause DoS condition on the target system.

The weakness exists due to a race condition in certain grant copy operations. A local attacker can trigger a memory corruption error in the hypervisor and cause the application to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

Xen

Debian Linux
SUSE Linux
Fedora
xen (Alpine package)
xen

How to mitigate CVE-2017-15597

Install update from vendor's website.

xen (Alpine package) - update to 4.6.6-r2
xen - addressed in versions 4.7.3-8.fc25, 4.8.2-5.fc26, 4.9.0-13.fc27

External References

Related Security Bulletins