CVE-2017-17046
medium
CVSS v3
6.5
CVSS v2
2.1
VIR risk
6.5
Description
An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, because disjoint blocks, and physical addresses that do not start at zero, are mishandled.
Predictions
Exploit likelihood
65%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-17046
Vendor advisory: cve@mitre.org — https://xenbits.xen.org/xsa/advisory-245.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 4.8.2+xsa245-0+deb9u1 |
| debian | bullseye | fixed | 4.8.2+xsa245-0+deb9u1 |
| debian | forky | fixed | 4.8.2+xsa245-0+deb9u1 |
| debian | sid | fixed | 4.8.2+xsa245-0+deb9u1 |
| debian | trixie | fixed | 4.8.2+xsa245-0+deb9u1 |
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.