CVE-2017-10911
Last modified
CVE-2017-10911 is a vulnerability of currently unknown severity. The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 4.11.7 |
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341Mailing List, Patch, Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/99162Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038720Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341Patch, Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-216.htmlMitigation, Vendor Advisory
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=089bc0143f489bd3a4578bdff5f4ca68fb26f341Mailing List, Patch, Third Party Advisory
- http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.11.8Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/99162Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038720Third Party Advisory, VDB Entry
- https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341Patch, Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-216.htmlMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-10911?
How severe is CVE-2017-10911?
How do I fix CVE-2017-10911?
Are you affected by CVE-2017-10911?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
