SB2017121226 - Fedora 27 update for xen
Published: December 12, 2017 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2017-15595)
The vulnerability allows an adjacent attacker to gain elevated privileges or cause DoS conditions on the target system.The weakness exists due to improper input validation. An adjacent attacker can supply specially crafted page-table stacking, trigger unbounded recursion, stack consumption, gain elevated privileges or cause hypervisor crash.
2) Denial of service (CVE-ID: CVE-2017-17566)
The vulnerability allows an adjacent attacker to cause DoS condition on the target system.The weakness exists due to improper auxiliary page mapping. A remote attacker can cause the system to crash.
3) Memory corruption (CVE-ID: CVE-2017-17563)
The vulnerability allows an adjacent attacker to gain elevated privileges or cause a denial of service (DoS) condition on a targeted host system.The weakness exists due to insufficient reference count overflow checking. An adjacent attacker can use a mask that is larger than the reference count that is set on a targeted system, trigger memory corruption and cause the hypervisor to crash or gain elevated privileges.
4) Denial of service (CVE-ID: CVE-2017-17564)
The vulnerability allows an adjacent attacker to cause DoS condition or gain elevated privileges.The weakness exists due to improper error handling for reference counts. A remote attacker can trigger memory corruption, cause the hypervisor to crash or gain elevated privileges on the target system.
5) Denial of service (CVE-ID: CVE-2017-17565)
The vulnerability allows an adjacent attacker to cause DoS condition on the target system.The weakness exists due to improper assertion related to machine-to-physical (M2P) translation table entries. A remote attacker can cause the system to crash.
Remediation
Install update from vendor's website.