Xen CVE-2017-17044 Denial of Service Vulnerability
BID:102008
Info
Xen CVE-2017-17044 Denial of Service Vulnerability
| Bugtraq ID: | 102008 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2017-17044 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2017 12:00AM |
| Updated: | Apr 03 2019 11:00AM |
| Credit: | Julien Grall of Linaro |
| Vulnerable: |
Xen Xen 4.9 Xen Xen 4.8 Xen Xen 4.7 Xen Xen 4.6 Xen Xen 4.6.3 Xen Xen 4.5.3 Xen Xen 4.5.0 Xen Xen 3.4.4 Xen Xen 3.4.3 Xen Xen 3.4.2 Xen Xen 3.4.1 Citrix XenServer 6.0.2 Citrix XenServer 7.2 Citrix XenServer 7.1 LTSR CU1 Citrix XenServer 7.1 Citrix XenServer 7.0 Citrix XenServer 6.5 Citrix XenServer 6.2 |
| Not Vulnerable: |
Citrix XenServer 6.0.2 Common Criteria Citrix XenServer 6.5 Service Pack 1 Citrix XenServer 6.2 Service Pack 1 |
Discussion
Xen CVE-2017-17044 Denial of Service Vulnerability
Xen is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition.
Xen versions 3.4.x and later are vulnerable.
Xen is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition.
Xen versions 3.4.x and later are vulnerable.
Exploit / POC
Xen CVE-2017-17044 Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen CVE-2017-17044 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Xen CVE-2017-17044 Denial of Service Vulnerability
References:
References:
- Bug 1513335 - (CVE-2017-17044, xsa246) CVE-2017-17044 xsa246 xen: x86: infinite (Red Hat)
- CVE-2017-17044 (Red Hat)
- x86/pod: prevent infinite loop when shattering large pages (Xen)
- x86/pod: prevent infinite loop when shattering large pages (Xen)
- x86/pod: prevent infinite loop when shattering large pages (Xen)
- Xen Homepage (XenSource )
- Citrix XenServer Multiple Security Updates (Citrix)
- Xen Security Advisory CVE-2017-17044 / XSA-246 (Xen)