{"api_version":"1","generated_at":"2026-07-23T08:17:14+00:00","cve":"CVE-2017-14319","urls":{"html":"https://cve.report/CVE-2017-14319","api":"https://cve.report/api/cve/CVE-2017-14319.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-14319","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-14319"},"summary":{"title":"CVE-2017-14319","description":"A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-09-12 15:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://support.citrix.com/article/CTX227185","name":"https://support.citrix.com/article/CTX227185","refsource":"CONFIRM","tags":[],"title":"Citrix XenServer Multiple Security Updates","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/100819","name":"100819","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Xen 'mm.c' Remote Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1039351","name":"1039351","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Xen Grant Unmapping Flaw Lets Local Users on a Guest System Gain Elevated Privileges or Cause Denial of Service Conditions on the Host System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://xenbits.xen.org/xsa/advisory-234.html","name":"http://xenbits.xen.org/xsa/advisory-234.html","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"XSA-234 - Xen Security Advisories","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2018/10/msg00009.html","name":"[debian-lts-announce] 20181018 [SECURITY] [DLA 1549-1] xen security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 1549-1] xen security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2017/dsa-4050","name":"DSA-4050","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4050-1 xen","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-14319","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14319","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"14319","vulnerable":"1","versionEndIncluding":"4.9.0","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"xen","cpe5":"xen","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-14319","qid":"500818","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2017-14319","qid":"504561","title":"Alpine Linux Security Update for xen"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-14319","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1039351","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1039351"},{"name":"https://support.citrix.com/article/CTX227185","refsource":"CONFIRM","url":"https://support.citrix.com/article/CTX227185"},{"name":"DSA-4050","refsource":"DEBIAN","url":"https://www.debian.org/security/2017/dsa-4050"},{"name":"100819","refsource":"BID","url":"http://www.securityfocus.com/bid/100819"},{"name":"[debian-lts-announce] 20181018 [SECURITY] [DLA 1549-1] xen security update","refsource":"MLIST","url":"https://lists.debian.org/debian-lts-announce/2018/10/msg00009.html"},{"name":"http://xenbits.xen.org/xsa/advisory-234.html","refsource":"CONFIRM","url":"http://xenbits.xen.org/xsa/advisory-234.html"}]}},"nvd":{"publishedDate":"2017-09-12 15:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*","versionEndIncluding":"4.9.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"14319","Ordinal":"111750","Title":"CVE-2017-14319","CVE":"CVE-2017-14319","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"14319","Ordinal":"1","NoteData":"A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"14319","Ordinal":"2","NoteData":"2017-09-12","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"14319","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}