Candidate: CVE-2017-14317 PublicDate: 2017-09-12 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14317 https://xenbits.xen.org/xsa/advisory-233.html Description: A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xenstored daemon may crash, resulting in a DoS of any parts of the system relying on it (including domain creation / destruction, ballooning, device changes, etc.). Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Eric Chanudet Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H [5.6 MEDIUM] Patches_xen: Tags_xen: universe-binary upstream_xen: needs-triage precise/esm_xen: DNE trusty_xen: released (4.4.2-0ubuntu0.14.04.14) trusty/esm_xen: DNE (trusty was released [4.4.2-0ubuntu0.14.04.14]) vivid/ubuntu-core_xen: DNE xenial_xen: released (4.6.5-0ubuntu1.4) esm-infra/xenial_xen: released (4.6.5-0ubuntu1.4) zesty_xen: released (4.8.0-1ubuntu2.4) devel_xen: released (4.9.0-0ubuntu3)