Lucene search

K
redhatcveRedhat.comRH:CVE-2017-10915
HistoryJul 07, 2017 - 2:53 p.m.

CVE-2017-10915

2017-07-0714:53:58
redhat.com
access.redhat.com
7

0.007 Low

EPSS

Percentile

80.9%

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

Mitigation

Where the HVM guest is explicitly configured to use shadow paging (eg
via the hap=0' xl domain configuration file parameter), changing to HAP (eg by setting hap=1') will avoid exposing the vulnerability to
those guests. HAP is the default (in upstream Xen), where the
hardware supports it; so this mitigation is only applicable if HAP has
been disabled by configuration.

(This mitigation is not applicable to PV guests.)