CVE-2017-15590: High severity XEN Xen vulnerability
Published Oct 18, 2017
·Updated
An issue was discovered in Xen through 4.9.x allowing x86 guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because MSI mapping was mishandled.
Affected Software
2 affected componentsFixes available
debian/xen
4.11.4+107-gef32c7afa2-14.14.6-14.14.5+94-ge49571868d-14.17.1+2-gb773c48e36-14.17.2+55-g0b56bed864-1
XEN Xen=4.9.0
Remediation
Patch Available
Event History
Oct 18, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15590?
CVE-2017-15590 is classified as high severity due to its potential to cause a hypervisor crash or privilege escalation.
2
How do I fix CVE-2017-15590?
To fix CVE-2017-15590, upgrade to a patched version of Xen such as 4.11.4+107-gef32c7afa2-1 or higher.
3
Which versions of Xen are affected by CVE-2017-15590?
CVE-2017-15590 affects Xen versions prior to 4.11.4, with specific impact noted on 4.9.x.
4
Can CVE-2017-15590 lead to data breaches?
While CVE-2017-15590 primarily causes denial of service, it may also allow x86 guest OS users to gain unauthorized privileges.
5
Is CVE-2017-15590 specific to certain operating systems?
CVE-2017-15590 specifically affects the Xen hypervisor, which can run on various operating systems hosting virtual machines.