{"api_version":"1","generated_at":"2026-07-23T10:47:04+00:00","cve":"CVE-2017-10911","urls":{"html":"https://cve.report/CVE-2017-10911","api":"https://cve.report/api/cve/CVE-2017-10911.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-10911","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-10911"},"summary":{"title":"CVE-2017-10911","description":"The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-07-05 01:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.9","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:N/A:N","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.debian.org/security/2017/dsa-3920","name":"http://www.debian.org/security/2017/dsa-3920","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3920-1 qemu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2017/dsa-3945","name":"http://www.debian.org/security/2017/dsa-3945","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3945-1 linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341","name":"https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"xen-blkback: don't leak stack data via response ring · torvalds/linux@089bc01 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8","name":"http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://xenbits.xen.org/xsa/advisory-216.html","name":"https://xenbits.xen.org/xsa/advisory-216.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Vendor Advisory"],"title":"XSA-216 - Xen Security Advisories","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2017/dsa-3927","name":"http://www.debian.org/security/2017/dsa-3927","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3927-1 linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html","name":"https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] [DLA 1497-1] qemu security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1038720","name":"http://www.securitytracker.com/id/1038720","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Xen Block Interface Response Initialization Error Lets Local Guest System Users Obtain Potentially Sensitive Information from Other Guest Systems or the Host System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/99162","name":"http://www.securityfocus.com/bid/99162","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Xen 'blkif' Response Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341","name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch","Third Party Advisory"],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201708-03","name":"https://security.gentoo.org/glsa/201708-03","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux — Error 404 (Not Found)","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-10911","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-10911","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"10911","vulnerable":"1","versionEndIncluding":"4.11.7","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-10911","qid":"500816","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2017-10911","qid":"504559","title":"Alpine Linux Security Update for xen"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T17:50:12.586Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://xenbits.xen.org/xsa/advisory-216.html"},{"name":"DSA-3927","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2017/dsa-3927"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341"},{"name":"DSA-3920","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2017/dsa-3920"},{"name":"[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html"},{"name":"GLSA-201708-03","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201708-03"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8"},{"name":"99162","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/99162"},{"name":"1038720","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1038720"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341"},{"name":"DSA-3945","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2017/dsa-3945"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-07-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-09-07T09:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://xenbits.xen.org/xsa/advisory-216.html"},{"name":"DSA-3927","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2017/dsa-3927"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341"},{"name":"DSA-3920","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2017/dsa-3920"},{"name":"[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html"},{"name":"GLSA-201708-03","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201708-03"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8"},{"name":"99162","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/99162"},{"name":"1038720","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1038720"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341"},{"name":"DSA-3945","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2017/dsa-3945"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-10911","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://xenbits.xen.org/xsa/advisory-216.html","refsource":"CONFIRM","url":"https://xenbits.xen.org/xsa/advisory-216.html"},{"name":"DSA-3927","refsource":"DEBIAN","url":"http://www.debian.org/security/2017/dsa-3927"},{"name":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341","refsource":"CONFIRM","url":"http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341"},{"name":"DSA-3920","refsource":"DEBIAN","url":"http://www.debian.org/security/2017/dsa-3920"},{"name":"[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update","refsource":"MLIST","url":"https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html"},{"name":"GLSA-201708-03","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201708-03"},{"name":"http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8","refsource":"CONFIRM","url":"http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8"},{"name":"99162","refsource":"BID","url":"http://www.securityfocus.com/bid/99162"},{"name":"1038720","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1038720"},{"name":"https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341","refsource":"CONFIRM","url":"https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341"},{"name":"DSA-3945","refsource":"DEBIAN","url":"http://www.debian.org/security/2017/dsa-3945"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2017-10911","datePublished":"2017-07-05T01:00:00.000Z","dateReserved":"2017-07-04T00:00:00.000Z","dateUpdated":"2024-08-05T17:50:12.586Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-07-05 01:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2,"impactScore":4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:N/A:N","baseScore":4.9,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndIncluding":"4.11.7","matchCriteriaId":"5556BED7-53AD-4C99-8470-F833F13AB73C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"10911","Ordinal":"1","Title":"CVE-2017-10911","CVE":"CVE-2017-10911","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"10911","Ordinal":"1","NoteData":"The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.","Type":"Description","Title":"CVE-2017-10911"},{"CveYear":"2017","CveId":"10911","Ordinal":"2","NoteData":"2017-07-04","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"10911","Ordinal":"3","NoteData":"2018-09-07","Type":"Other","Title":"Modified"}]}}}