← Back

CVE-2017-7995

nvd nist
Published: May 3, 2017Modified: May 13, 2026

JSON object

Loading...
3.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Exploitability: 2.0 / Impact: 1.4
Source: NVD

Description

Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.

Affected (6)

1 product
Xen
2 products
Suse Linux Enterprise Server
3 products
Manager
Manager Proxy
Openstack Cloud
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.2.5
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0 sp3
Version 11.0 sp3
Version 2.1
Version 2.1
Version 5

References (6)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party AdvisoryVDB Entry

Timeline

No history available yet.