The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1099-1 | linux security update |
Debian DLA |
DLA-1497-1 | qemu security update |
Debian DSA |
DSA-3920-1 | qemu security update |
Debian DSA |
DSA-3927-1 | linux security update |
Debian DSA |
DSA-3945-1 | linux security update |
EUVD |
EUVD-2017-2549 | The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216. |
Ubuntu USN |
USN-3414-1 | QEMU vulnerabilities |
Ubuntu USN |
USN-3468-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3468-2 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-3468-3 | Linux kernel (GCP) vulnerabilities |
Ubuntu USN |
USN-3469-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3469-2 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-3470-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3470-2 | Linux kernel (Trusty HWE) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T17:50:12.586Z
Reserved: 2017-07-04T00:00:00
Link: CVE-2017-10911
No data.
Status : Deferred
Published: 2017-07-05T01:29:00.550
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-10911
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN