CVE-2017-10911

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-10911
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-10911.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-10911
Downstream
Related
Published
2017-07-05T01:29:00Z
Modified
2025-08-09T20:01:27Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.

References

Affected packages