CVE-2017-10911

Source
https://cve.org/CVERecord?id=CVE-2017-10911
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-10911.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-10911
Downstream
Related
Published
2017-07-05T01:29:00.550Z
Modified
2026-03-15T22:13:35.808352Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-10911.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.11.7"
            }
        ]
    }
]