CVE-2017-15594: High severity XEN Xen vulnerability
Published Oct 18, 2017
·Updated
An issue was discovered in Xen through 4.9.x allowing x86 SVM PV guest OS users to cause a denial of service (hypervisor crash) or gain privileges because IDT settings are mishandled during CPU hotplugging.
Affected Software
2 affected componentsFixes available
debian/xen
4.11.4+107-gef32c7afa2-14.14.6-14.14.5+94-ge49571868d-14.17.1+2-gb773c48e36-14.17.2+55-g0b56bed864-1
XEN Xen<=4.9.0
Remediation
Patch Available
Event History
Oct 18, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15594?
CVE-2017-15594 has a high severity rating due to its potential to cause a hypervisor crash or privilege escalation.
2
How do I fix CVE-2017-15594?
To fix CVE-2017-15594, upgrade to a version of Xen that is 4.11.4+107-gef32c7afa2-1 or higher.
3
What versions of Xen are affected by CVE-2017-15594?
CVE-2017-15594 affects all Xen versions up to and including 4.9.x.
4
What impact does CVE-2017-15594 have on users?
CVE-2017-15594 allows x86 SVM PV guest OS users to potentially crash the hypervisor or gain elevated privileges.
5
Is there a workaround for CVE-2017-15594?
There are no known effective workarounds for CVE-2017-15594, and upgrading is the recommended approach.