CVE-2017-15594
Gentoo Linux Security Advisory 201801-14
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Xen through 4.9.x allowing x86 SVM PV guest OS users to cause a denial of service (hypervisor crash) or gain privileges because IDT settings are mishandled during CPU hotplugging.
Se ha descubierto un problema en Xen hasta las versiones 4.9.x que permite que usuarios invitados del sistema operativo x86 SVM PV provoquen una denegación de servicio (cierre inesperado del hipervisor) o que puedan obtener privilegios debido a que se gestionó de manera incorrecta la configuración IDT durante la conexión directa a la CPU.
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, information leaks, privilege escalation or the execution of arbitrary code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-18 CVE Reserved
- 2017-10-18 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1039568 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2018/10/msg00021.html | Mailing List |
|
https://support.citrix.com/article/CTX228867 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://xenbits.xen.org/xsa/advisory-244.html | 2019-10-03 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201801-14 | 2019-10-03 | |
https://www.debian.org/security/2017/dsa-4050 | 2019-10-03 |