CVE-2017-10917 PUBLISHED

Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.

EPSS 0.84% · 74.6th percentile

Risk Scores

EPSS Score
0.84%
74.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSxen0, 4.5.1-0ubuntu1, 4.5.1-0ubuntu2
Ubuntu:14.04:LTSxen4.4.1-0ubuntu0.14.04.1, 4.4.1-0ubuntu0.14.04.2, 4.4.1-0ubuntu0.14.04.3

Timeline

References

Open in Interactive Console →