~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
Candidate: CVE-2017-7228
PublicDate: 2017-04-04
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7228
 https://xenbits.xen.org/xsa/advisory-212.html
 http://openwall.com/lists/oss-security/2017/04/04/3
Description:
 An issue (known as XSA-212) was discovered in Xen, with fixes available for
 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an
 insufficient check on XENMEM_exchange input, allowing the caller to drive
 hypervisor memory accesses outside of the guest provided input/output
 arrays.
Ubuntu-Description:
Notes:
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=859560
Priority: medium
Discovered-by: Jann Horn
Assigned-to:

Patches_xen:
Tags_xen: universe-binary
upstream_xen: needs-triage
precise_xen: ignored (reached end-of-life)
precise/esm_xen: DNE (precise was needs-triage)
trusty_xen: released (4.4.2-0ubuntu0.14.04.11)
vivid/ubuntu-core_xen: DNE
vivid/stable-phone-overlay_xen: DNE
xenial_xen: released (4.6.5-0ubuntu1.1)
yakkety_xen: released (4.7.2-0ubuntu1.2)
zesty_xen: released (4.8.0-1ubuntu2.1)
devel_xen: needed