CVE-2017-7228: Out-of-bounds Read
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEMexchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch XSA-212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.8.xPatch XSA-212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.7.xPatch XSA-212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.xPatch XSA-212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.5.xPatch XSA-212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.4.xPatch XSA-212
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector identifies this as a local attack requiring high privileges. No user interaction is required.
Which Xen release branches had fixes available?
Fixes were available for Xen 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The provided information does not identify the specific fixed maintenance releases.
What security impact is indicated if exploitation succeeds?
The CVSS vector rates confidentiality, integrity, and availability impact as high, with scope changed. The flaw lets a caller cause hypervisor memory accesses outside the guest-provided input and output arrays.