CVE-2017-15589
Last modified
CVE-2017-15589 is a vulnerability of currently unknown severity. An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the host OS (or an arbitrary guest OS) because intercepted I/O operations can cause a write of data from uninitialized hypervisor stack memory.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the host OS (or an arbitrary guest OS) because intercepted I/O operations can cause a write of data from uninitialized hypervisor stack memory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | 4.9.0 |
References
- http://www.securityfocus.com/bid/101496Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039568Third Party Advisory, VDB Entry
- https://xenbits.xen.org/xsa/advisory-239.htmlMailing List, Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101496Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039568Third Party Advisory, VDB Entry
- https://xenbits.xen.org/xsa/advisory-239.htmlMailing List, Mitigation, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-15589?
How severe is CVE-2017-15589?
How do I fix CVE-2017-15589?
Are you affected by CVE-2017-15589?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
