CVE-2017-8904: High severity xen xapi vulnerability
Published May 11, 2017
·Updated
Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOPtransfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.
Affected Software
2 affected components
Xen XAPI=4.8.0
Xen XAPI=4.8.1
Remediation
Patch Available
Event History
May 11, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8904?
CVE-2017-8904 has a high severity rating due to its potential to allow arbitrary code execution on the host OS.
2
How do I fix CVE-2017-8904?
To remediate CVE-2017-8904, upgrade to Xen versions 4.8.2 or later.
3
Who is affected by CVE-2017-8904?
Users running Xen versions 4.8.0 and 4.8.1 are affected by CVE-2017-8904.
4
What type of vulnerability is CVE-2017-8904?
CVE-2017-8904 is a code execution vulnerability that affects the guest transfer operations in Xen.
5
Can CVE-2017-8904 be exploited remotely?
Yes, CVE-2017-8904 may be exploited by privileged users on the guest OS to execute code on the host OS.