Release Date: | 2017-09-12 | |
Impact: | Important | What is this? |
A grant unmapping issue was discovered in Xen through 4.9.x. Whenremoving or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.
See more information about CVE-2017-14319 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
Base Score: | 7.2 |
Vector String: | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Version: | 2.0 |
Attack Vector: | Local |
Attack Complexity: | Low |
Authentication: | None |
Confidentiality Impact: | Complete |
Integrity Impact: | Complete |
Availability Impact: | Complete |
Platform | Errata | Release Date |
Oracle VM version 3.2 (xen) | OVMSA-2017-0159 | 2017-10-24 |
Oracle VM version 3.3 (xen) | OVMSA-2017-0158 | 2017-10-24 |
Oracle VM version 3.4 (xen) | OVMSA-2017-0157 | 2017-10-24 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: