An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1549-1 xen security update
Debian DSA Debian DSA DSA-4050-1 xen security update
EUVD EUVD EUVD-2017-7049 An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T19:57:27.292Z

Reserved: 2017-10-18T00:00:00

Link: CVE-2017-15597

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-10-30T14:29:00.847

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-15597

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-10-24T00:00:00Z

Links: CVE-2017-15597 - Bugzilla

cve-icon OpenCVE Enrichment

No data.