The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.
2017-08-24T14:29:00.193
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | xen | xen | * | Yes |
Application | citrix | xenserver | 6.0.2 | Yes |
Application | citrix | xenserver | 6.2.0 | Yes |
Application | citrix | xenserver | 6.5 | Yes |
Application | citrix | xenserver | 7.0 | Yes |
Application | citrix | xenserver | 7.1 | Yes |
Application | citrix | xenserver | 7.2 | Yes |