Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-05-03T19:00:00
Updated: 2024-08-05T16:19:29.765Z
Reserved: 2017-04-21T00:00:00
Link: CVE-2017-7995
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-05-03T19:59:00.143
Modified: 2024-11-21T03:33:07.640
Link: CVE-2017-7995
Redhat