← Back

CVE-2017-10916

nvd nist
Published: Jul 5, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.

Affected (13)

Products: Xen: Xen
1 product
Xen
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Xen
Version 4.5.0
Version 4.5.1
Version 4.5.2
Version 4.5.3
Version 4.5.5
Version 4.6.0
Version 4.6.1
Version 4.6.2
Version 4.6.4
Version 4.6.5
Version 4.7.1
Version 4.8.0
Version 4.8.1

References (10)

Source: cve@mitre.org
Mailing ListMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationVendor Advisory

Timeline

No history available yet.