CVE-2017-10915: Race Condition
Published Jul 5, 2017
·Updated
The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
Affected Software
1 affected component
XEN Xen<=4.8.1
Event History
Jul 5, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10915?
CVE-2017-10915 is considered a high severity vulnerability due to its potential to allow unauthorized access to Xen privileges.
2
How does CVE-2017-10915 affect users of Xen virtualization?
CVE-2017-10915 allows guest OS users to escalate their privileges, which can compromise the security of the entire virtualization host.
3
How do I fix CVE-2017-10915?
To fix CVE-2017-10915, users should upgrade to Xen version 4.8.2 or later.
4
Which versions of Xen are affected by CVE-2017-10915?
CVE-2017-10915 affects Xen versions up to and including 4.8.1.
5
What is the attack vector for CVE-2017-10915?
The attack vector for CVE-2017-10915 involves exploiting a race condition in the shadow-paging feature of Xen.