CVE-2017-15589

medium
Published 2017-10-18 · Modified 2026-05-13
CVSS v3
6.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS v2
2.1
VIR risk
6.5

Description

An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the host OS (or an arbitrary guest OS) because intercepted I/O operations can cause a write of data from uninitialized hypervisor stack memory.

Predictions

Exploit likelihood
65%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-15589

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2017-15589.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://xenbits.xen.org/xsa/advisory-239.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed4.8.2+xsa245-0+deb9u1
debian debianbullseyefixed4.8.2+xsa245-0+deb9u1
debian debianforkyfixed4.8.2+xsa245-0+deb9u1
debian debiansidfixed4.8.2+xsa245-0+deb9u1
debian debiantrixiefixed4.8.2+xsa245-0+deb9u1

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.