Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-12855
Description:Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected.
Test IDs: 1.3.6.1.4.1.25623.1.0.891132   1.3.6.1.4.1.25623.1.0.703969  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-12855
BugTraq ID: 100341
http://www.securityfocus.com/bid/100341
Debian Security Information: DSA-3969 (Google Search)
http://www.debian.org/security/2017/dsa-3969
http://www.securitytracker.com/id/1039177




© 1998-2025 E-Soft Inc. All rights reserved.