CVE-2017-7228

Priority
Medium
Description
An issue (known as XSA-212) was discovered in Xen, with fixes available for
4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an
insufficient check on XENMEM_exchange input, allowing the caller to drive
hypervisor memory accesses outside of the guest provided input/output
arrays.
References
Bugs
Package
Source: xen (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 17.10 (Artful Aardvark):needed
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needs-triage)
Ubuntu 14.04 LTS (Trusty Tahr):released (4.4.2-0ubuntu0.14.04.11)
Ubuntu Touch 15.04:DNE
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (4.6.5-0ubuntu1.1)
Ubuntu 16.10 (Yakkety Yak):released (4.7.2-0ubuntu1.2)
Ubuntu 17.04 (Zesty Zapus):released (4.8.0-1ubuntu2.1)
More Information

Updated: 2017-05-15 14:14:15 UTC (commit 12551)