Unknown
CVE-2017-14316
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
CVE-2017-14316
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A parameter verification issue was discovered in Xen through 4.9.x. The function alloc_heap_pages
allows callers to specify the first NUMA node that should be used for allocations through the memflags
parameter; the node is extracted using the MEMF_get_node
macro. While the function checks to see if the special constant NUMA_NO_NODE
is specified, it otherwise does not handle the case where node >= MAX_NUMNODES
. This allows an out-of-bounds access to an internal array.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- xen
Products
- xen
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: