← Back

CVE-2017-12855

nvd nist
Published: Aug 15, 2017Modified: May 13, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Exploitability: 2.0 / Impact: 4.0
Source: NVD

Description

Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected.

Affected (18)

Products: Xen: Xen
1 product
Xen
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Xen
Version 4.5.0
Version 4.5.1
Version 4.5.2
Version 4.5.3
Version 4.5.5
Version 4.6.0
Version 4.6.1
Version 4.6.3
Version 4.6.4
Version 4.6.5
Version 4.6.6
Version 4.7.0
Version 4.7.1
Version 4.7.2
Version 4.7.3
Version 4.8.0
Version 4.8.1
Version 4.9.0

References (10)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.