CVE-2017-14319
Summary
| CVE | CVE-2017-14319 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-12 15:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Citrix XenServer Multiple Security Updates | CONFIRM | support.citrix.com | |
| Xen 'mm.c' Remote Privilege Escalation Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Xen Grant Unmapping Flaw Lets Local Users on a Guest System Gain Elevated Privileges or Cause Denial of Service Conditions on the Host System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| XSA-234 - Xen Security Advisories | CONFIRM | xenbits.xen.org | Patch, Vendor Advisory |
| [SECURITY] [DLA 1549-1] xen security update | MLIST | lists.debian.org | |
| Debian -- Security Information -- DSA-4050-1 xen | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.