Candidate: CVE-2017-12136 PublicDate: 2017-08-24 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12136 https://xenbits.xen.org/xsa/advisory-228.html Description: Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling. Ubuntu-Description: Notes: sbeattie> xen 4.6 and later are vulnerable Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H [7.8 HIGH] Patches_xen: Tags_xen: universe-binary upstream_xen: needs-triage precise/esm_xen: DNE trusty_xen: not-affected trusty/esm_xen: DNE (trusty was not-affected) vivid/ubuntu-core_xen: DNE xenial_xen: released (4.6.5-0ubuntu1.4) esm-infra/xenial_xen: released (4.6.5-0ubuntu1.4) zesty_xen: released (4.8.0-1ubuntu2.4) devel_xen: released (4.9.0-0ubuntu1)