CVE-2017-10918
UnknownEPSS 3.67%
Last modified
CVE-2017-10918 is a vulnerability of currently unknown severity. Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.. EPSS estimates a 3.67% chance of exploitation in the next 30 days.
Description
Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | <= 4.8.1 |
References
- http://www.securityfocus.com/bid/99161Third Party Advisory, VDB Entry
- https://xenbits.xen.org/xsa/advisory-222.htmlMailing List, Mitigation, Third Party Advisory
- http://www.securityfocus.com/bid/99161Third Party Advisory, VDB Entry
- https://xenbits.xen.org/xsa/advisory-222.htmlMailing List, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-10918?
Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.
How severe is CVE-2017-10918?
Severity scoring for CVE-2017-10918 is pending analysis. The EPSS model estimates a 3.67% probability of exploitation in the next 30 days.
How do I fix CVE-2017-10918?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-10912Xen through 4.8.x mishandles page transfer, which allows gue…
- CVE-2017-10913The grant-table feature in Xen through 4.8.x provides false …
- CVE-2017-10914The grant-table feature in Xen through 4.8.x has a race cond…
- CVE-2017-10915The shadow-paging feature in Xen through 4.8.x mismanages pa…
- CVE-2017-10916The vCPU context-switch implementation in Xen through 4.8.x …
- CVE-2017-10917Xen through 4.8.x does not validate the port numbers of poll…
- CVE-2017-10919Xen through 4.8.x mishandles virtual interrupt injection, wh…
- CVE-2017-1092IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allo…
- CVE-2017-10920The grant-table feature in Xen through 4.8.x mishandles a GN…
- CVE-2017-10921The grant-table feature in Xen through 4.8.x does not ensure…
- CVE-2017-10922The grant-table feature in Xen through 4.8.x mishandles MMIO…
- CVE-2017-10923Xen through 4.8.x does not validate a vCPU array index upon …
Are you affected by CVE-2017-10918?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
