Lucene search

K
redhatcveRedhat.comRH:CVE-2017-10919
HistoryJul 07, 2017 - 2:51 p.m.

CVE-2017-10919

2017-07-0714:51:39
redhat.com
access.redhat.com
13

0.003 Low

EPSS

Percentile

69.0%

Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.

Mitigation

On systems where the guest kernel is controlled by the host rather than
guest administrator, running only kernels which do not disable SGI and
PPI (i.e IRQ < 32) will prevent untrusted guest users from exploiting
this issue. However untrusted guest administrators can still trigger it
unless further steps are taken to prevent them from loading code into
the kernel (e.g by disabling loadable modules etc) or from using other
mechanisms which allow them to run code at kernel privilege.

0.003 Low

EPSS

Percentile

69.0%