CVE-2017-12134

Description

The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.339

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Citrix XenCenter 6.0.2Windows
Multiple Vulnerabilities are affected in Citrix XenCenter 6.2.0Windows
Multiple Vulnerabilities are affected in Citrix XenCenter 6.5Windows
Multiple Vulnerabilities are affected in Citrix XenCenter 7.0Windows
Multiple Vulnerabilities are affected in Citrix XenCenter 7.1Windows
Multiple Vulnerabilities are affected in Citrix XenCenter 7.2Windows
Linux hardware enablement kernel from Xenial for Trusty (USN-3444-2) linux-image-4.4.0-97-generic_4.4.0-97.120~14.04.1_i386.debLinux
Linux hardware enablement kernel from Xenial for Trusty (USN-3444-2) linux-image-4.4.0-97-generic_4.4.0-97.120~14.04.1_amd64.debLinux
Linux hardware enablement kernel from Xenial for Trusty (USN-3444-2) linux-image-4.4.0-97-lowlatency_4.4.0-97.120~14.04.1_i386.debLinux
Linux hardware enablement kernel from Xenial for Trusty (USN-3444-2) linux-image-4.4.0-97-lowlatency_4.4.0-97.120~14.04.1_amd64.debLinux
Linux kernel (USN-3219-1) linux-image-generic_3.13.0.149.159_amd64.debLinux
Linux kernel (USN-3219-1) linux-image-lowlatency_3.13.0.149.159_amd64.debLinux
Linux kernel (USN-3594-1) linux-image-generic_3.13.0.149.159_i386.debLinux
Linux kernel (USN-3594-1) linux-image-lowlatency_3.13.0.149.159_i386.debLinux
Linux kernel (USN-3655-1) linux-image-3.13.0-149-generic_3.13.0-149.199_i386.debLinux
Linux kernel (USN-3655-1) linux-image-3.13.0-149-generic_3.13.0-149.199_amd64.debLinux
Linux kernel (USN-3655-1) linux-image-3.13.0-149-lowlatency_3.13.0-149.199_i386.debLinux
Linux kernel (USN-3655-1) linux-image-3.13.0-149-lowlatency_3.13.0-149.199_amd64.debLinux
Dtrace-modules-3.8.13-118.19.7.el6uek update (ELSA-2017-3621) dtrace-modules-3.8.13-118.19.7.el6uek-0.4.5-3.el6.x86_64.rpmLinux
Dtrace-modules-3.8.13-118.19.7.el7uek update (ELSA-2017-3621) dtrace-modules-3.8.13-118.19.7.el7uek-0.4.5-3.el7.x86_64.rpmLinux
Dtrace-modules-3.8.13-118.20.1.el6uek update (ELSA-2017-3657) dtrace-modules-3.8.13-118.20.1.el6uek-0.4.5-3.el6.x86_64.rpmLinux
Dtrace-modules-3.8.13-118.20.1.el7uek update (ELSA-2017-3657) dtrace-modules-3.8.13-118.20.1.el7uek-0.4.5-3.el7.x86_64.rpmLinux
Incorrect Calculation Vulnerability (CVE-2017-12134)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234