vulnerability
Alpine Linux: CVE-2017-10911: Exposure of Sensitive Information to an Unauthorized Actor
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:N/C:C/I:N/A:N) | Jul 5, 2017 | Oct 27, 2017 | Mar 25, 2026 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:C/I:N/A:N)
Published
Jul 5, 2017
Added
Oct 27, 2017
Modified
Mar 25, 2026
Description
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
Solution
alpine-linux-upgrade-xen
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.