Denial of service in xen (Alpine package)



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2017-17564
CWE-ID CWE-388
Exploitation vector Local network
Public exploit N/A
Vulnerable software
xen (Alpine package)
Operating systems & Components / Operating system package or component

Vendor Alpine Linux Development Team

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Denial of service

EUVDB-ID: #VU10616

Risk: Low

CVSSv4.0: 6.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2017-17564

CWE-ID: CWE-388 - Error Handling

Exploit availability: No

Description

The vulnerability allows an adjacent attacker to cause DoS condition or gain elevated privileges.

The weakness exists due to improper error handling for reference counts. A remote attacker can trigger memory corruption, cause the hypervisor to crash or gain elevated privileges on the target system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

xen (Alpine package): 4.5.0-r0 - 4.6.6-r2

CPE2.3 External links

https://git.alpinelinux.org/aports/commit/?id=6e2ae39b5d0e697b956f42282f5cb9e6ecfb2e29
https://git.alpinelinux.org/aports/commit/?id=8a03efa3f54d603aed0da0d4fd9b7439388a64cd
https://git.alpinelinux.org/aports/commit/?id=2e27888986ee5f1a314e43e670e33e3ba45fe107


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###