Vulnerability Description
Memory leak in Xen 3.3 through 4.8.x allows guest OS users to cause a denial of service (ARM or x86 AMD host OS memory consumption) by continually rebooting, because certain cleanup is skipped if no pass-through device was ever assigned, aka XSA-207.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | 3.3.0 |
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2018/09/msg00006.html
- https://xenbits.xen.org/xsa/advisory-207.htmlMitigationPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00006.html
- https://xenbits.xen.org/xsa/advisory-207.htmlMitigationPatchVendor Advisory
FAQ
What is CVE-2017-14431?
CVE-2017-14431 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Memory leak in Xen 3.3 through 4.8.x allows guest OS users to cause a denial of service (ARM or x86 AMD host OS memory consumption) by continually rebooting, because certain cleanup is skipped if no p...
How severe is CVE-2017-14431?
CVE-2017-14431 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14431?
Check the references section above for vendor advisories and patch information. Affected products include: Xen Xen.