CVE-2017-17044: Medium severity XEN Xen vulnerability
Published Nov 28, 2017
·Updated
An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and host OS hang) by leveraging the mishandling of Populate on Demand (PoD) errors.
Affected Software
2 affected componentsFixes available
debian/xen
4.11.4+107-gef32c7afa2-14.14.6-14.14.5+94-ge49571868d-14.17.1+2-gb773c48e36-14.17.2+55-g0b56bed864-1
XEN Xen<=4.9.1
Remediation
Patch Available
Event History
Nov 28, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17044?
CVE-2017-17044 has a high severity rating due to its potential to cause a denial of service through host OS hang.
2
How do I fix CVE-2017-17044?
To fix CVE-2017-17044, upgrade to Xen version 4.11.4+107-gef32c7afa2-1 or later, or any version higher than 4.9.1.
3
What versions of Xen are affected by CVE-2017-17044?
CVE-2017-17044 affects Xen versions up to and including 4.9.1.
4
What type of vulnerability is CVE-2017-17044?
CVE-2017-17044 is a denial of service vulnerability impacting HVM guest OS users.
5
Can user-level processes exploit CVE-2017-17044?
Yes, user-level processes in HVM guest OS can exploit CVE-2017-17044 by causing an infinite loop and thus hang the host OS.