CVE-2017-10918: Input Validation
Published Jul 5, 2017
·Updated
Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.
Affected Software
1 affected component
XEN Xen<=4.8.1
Event History
Jul 5, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10918?
CVE-2017-10918 is rated as high severity due to the potential for guest OS users to gain privileged host OS access.
2
How do I fix CVE-2017-10918?
To fix CVE-2017-10918, users should upgrade to Xen version 4.8.2 or later, where the memory allocation validation issue has been resolved.
3
Who is affected by CVE-2017-10918?
CVE-2017-10918 affects users running Xen versions up to and including 4.8.1.
4
What type of vulnerability is CVE-2017-10918?
CVE-2017-10918 is a privilege escalation vulnerability caused by improper validation of memory allocations in certain P2M operations.
5
What are the potential consequences of CVE-2017-10918?
The potential consequences of CVE-2017-10918 include unauthorized access to the host OS by a compromised guest OS.