Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-07-05T01:00:00

Updated: 2017-11-03T18:57:01

Reserved: 2017-07-04T00:00:00


Link: CVE-2017-10917

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2017-07-05T01:29:00.737

Modified: 2017-11-04T01:29:31.943


Link: CVE-2017-10917

JSON object: View

cve-icon Redhat Information

No data.

CWE