CVE-2017-15591: Input Validation
Published Oct 18, 2017
·Updated
An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) to cause a denial of service (host OS crash) because of a missing comparison (of range start to range end) within the DMOP map/unmap implementation.
Affected Software
18 affected components
XEN Xen=4.5.0
XEN Xen=4.5.1
XEN Xen=4.5.2
XEN Xen=4.5.3
XEN Xen=4.5.5
XEN Xen=4.6.0
XEN Xen=4.6.1
XEN Xen=4.6.3
XEN Xen=4.6.4
XEN Xen=4.6.5
XEN Xen=4.6.6
XEN Xen=4.7.0
XEN Xen=4.7.1
XEN Xen=4.7.2
XEN Xen=4.7.3
XEN Xen=4.8.0
XEN Xen=4.8.1
XEN Xen=4.9.0
Remediation
Patch Available
Event History
Oct 18, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15591?
CVE-2017-15591 has a moderate severity level, allowing for denial of service attacks against the host OS.
2
How do I fix CVE-2017-15591?
To fix CVE-2017-15591, users should upgrade to the latest version of Xen that addresses this vulnerability.
3
Which versions of Xen are affected by CVE-2017-15591?
CVE-2017-15591 affects Xen versions from 4.5.x through 4.9.x.
4
What type of attack does CVE-2017-15591 enable?
CVE-2017-15591 enables attackers to cause a denial of service by crashing the host operating system.
5
Who is vulnerable to CVE-2017-15591?
Users controlling a stub domain kernel or tool stack are vulnerable to CVE-2017-15591.