Bug 1771349 (CVE-2019-17340) - CVE-2019-17340 xen: mishanding grant-table transfer allows x86 guest OS to cause a DoS or escalate their privileges
Summary: CVE-2019-17340 xen: mishanding grant-table transfer allows x86 guest OS to ca...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2019-17340
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1771350
Blocks: 1762982
TreeView+ depends on / blocked
 
Reported: 2019-11-12 08:52 UTC by Marian Rehak
Modified: 2020-05-06 14:16 UTC (History)
23 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2020-02-24 15:09:44 UTC
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2019-11-12 08:52:32 UTC
When the code processing grant table transfer requests finds a page with an address too large to be represented in the interface with the guest, it allocates a replacement page and copies page contents. The page as well as certain other remnants of an affected guest will be leaked due to being unfreeable upon domain cleanup.

Comment 1 Marian Rehak 2019-11-12 08:52:59 UTC
Created xen tracking bugs for this issue:

Affects: fedora-all [bug 1771350]

Comment 2 Marian Rehak 2019-11-12 08:53:16 UTC
Upstream issue and patch:

https://xenbits.xen.org/xsa/advisory-284.html


Note You need to log in before you can comment on or make changes to this bug.