CVE-2017-8904

Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:xen:xen:4.8.0:*:*:*:*:*:*:*
cpe:2.3:o:xen:xen:4.8.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-05-11 19:29

Updated : 2023-12-10 12:01


NVD link : CVE-2017-8904

Mitre link : CVE-2017-8904

CVE.ORG link : CVE-2017-8904


JSON object : View

Products Affected

xen

  • xen