A parameter verification issue was discovered in Xen through 4.9.x. The function `alloc_heap_pages` allows callers to specify the first NUMA node that should be used for allocations through the `memflags` parameter; the node is extracted using the `MEMF_get_node` macro. While the function checks to see if the special constant `NUMA_NO_NODE` is specified, it otherwise does not handle the case where `node >= MAX_NUMNODES`. This allows an out-of-bounds access to an internal array.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Oct 26, 2017 | Sep 12, 2017 |
| Debian | — | Upgrade xen | Nov 29, 2017 | Sep 12, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 12, 2017 |
| Suse | — | Upgrade xenUpgrade xen-tools-domuUpgrade xen-doc-htmlUpgrade xen-kmp-paeUpgrade xen-libsUpgrade xen-doc-pdfUpgrade xen-kmp-defaultUpgrade xen-libs-32bitUpgrade xen-develUpgrade xen-tools | Sep 13, 2017 | Sep 12, 2017 |
| Ubuntu | — | Upgrade xen | Nov 19, 2024 | Sep 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub