CVE-2017-14319: High severity xen xapi vulnerability
A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14319?
CVE-2017-14319 is classified as a medium severity vulnerability.
How do I fix CVE-2017-14319?
To fix CVE-2017-14319, upgrade Xen to version 4.11.4+107-gef32c7afa2-1 or later.
What causes CVE-2017-14319?
CVE-2017-14319 is caused by a grant unmapping issue in Xen that leads to inconsistencies in page table entries.
Which versions of Xen are affected by CVE-2017-14319?
CVE-2017-14319 affects Xen versions up to and including 4.9.0.
Is CVE-2017-14319 specific to any architecture?
Yes, CVE-2017-14319 is specific to the x86 PV (paravirtualized) architecture of Xen.