CVE-2017-12136

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.

References

http://www.debian.org/security/2017/dsa-3969

http://www.openwall.com/lists/oss-security/2017/08/15/3

http://www.securityfocus.com/bid/100346

http://www.securitytracker.com/id/1039175

http://xenbits.xen.org/xsa/advisory-228.html

https://bugzilla.redhat.com/show_bug.cgi?id=1477651

https://security.gentoo.org/glsa/201801-14

https://support.citrix.com/article/CTX225941

Details

Source: MITRE

Published: 2017-08-24

Updated: 2019-05-06

Type: CWE-362

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Impact Score: 6

Exploitability Score: 1.1

Severity: HIGH

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
140019OracleVM 3.4 : xen (OVMSA-2020-0039) (Bunker Buster) (Foreshadow) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (Meltdown) (POODLE) (Spectre)NessusOracleVM Local Security Checks
critical
111992OracleVM 3.4 : xen (OVMSA-2018-0248) (Bunker Buster) (Foreshadow) (Meltdown) (POODLE) (Spectre)NessusOracleVM Local Security Checks
critical
106038GLSA-201801-14 : Xen: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
104649SUSE SLES12 Security Update : xen (SUSE-SU-2017:2327-2)NessusSuSE Local Security Checks
high
103830OracleVM 3.4 : xen (OVMSA-2017-0153)NessusOracleVM Local Security Checks
critical
103342Fedora 25 : xen (2017-ed735463e3)NessusFedora Local Security Checks
high
103159openSUSE Security Update : xen (openSUSE-2017-1023)NessusSuSE Local Security Checks
high
103158openSUSE Security Update : xen (openSUSE-2017-1022)NessusSuSE Local Security Checks
critical
103146Debian DSA-3969-1 : xen - security updateNessusDebian Local Security Checks
critical
102953SUSE SLED12 Security Update : xen (SUSE-SU-2017:2327-1)NessusSuSE Local Security Checks
high
102952SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2017:2326-1)NessusSuSE Local Security Checks
critical
102835OracleVM 3.4 : xen (OVMSA-2017-0142)NessusOracleVM Local Security Checks
critical
102686Fedora 26 : xen (2017-f336ba205d)NessusFedora Local Security Checks
high
102585Xen Hypervisor Multiple Vulnerabilities (XSA-226 - XSA-230)NessusMisc.
high
102526Citrix XenServer Multiple Vulnerabilities (CTX225941)NessusMisc.
high