First published: Wed Oct 18 2017(Updated: )
An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) to cause a denial of service (host OS crash) because of a missing comparison (of range start to range end) within the DMOP map/unmap implementation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | =4.5.0 | |
Xen xen-unstable | =4.5.1 | |
Xen xen-unstable | =4.5.2 | |
Xen xen-unstable | =4.5.3 | |
Xen xen-unstable | =4.5.5 | |
Xen xen-unstable | =4.6.0 | |
Xen xen-unstable | =4.6.1 | |
Xen xen-unstable | =4.6.3 | |
Xen xen-unstable | =4.6.4 | |
Xen xen-unstable | =4.6.5 | |
Xen xen-unstable | =4.6.6 | |
Xen xen-unstable | =4.7.0 | |
Xen xen-unstable | =4.7.1 | |
Xen xen-unstable | =4.7.2 | |
Xen xen-unstable | =4.7.3 | |
Xen xen-unstable | =4.8.0 | |
Xen xen-unstable | =4.8.1 | |
Xen xen-unstable | =4.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15591 has a moderate severity level, allowing for denial of service attacks against the host OS.
To fix CVE-2017-15591, users should upgrade to the latest version of Xen that addresses this vulnerability.
CVE-2017-15591 affects Xen versions from 4.5.x through 4.9.x.
CVE-2017-15591 enables attackers to cause a denial of service by crashing the host operating system.
Users controlling a stub domain kernel or tool stack are vulnerable to CVE-2017-15591.