The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-10911.json"
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@089bc0143f489bd3a4578bdff5f4ca68fb26f341",
"digest": {
"line_hashes": [
"305295687626261053628472062535625123130",
"241527122757668286491981042048444794031",
"29214158053353921995836630380706418143",
"59448085497753006688546955463935321113",
"178059486168661006060467830429192716717",
"73190716207628327542462847775776559268",
"19295807819882618871017299414403253613",
"41640409495128892964422877466409100409",
"135287371340885021688015520453273931549",
"111568502628415160616006692559373372137",
"39608293214316973445192847671650433368",
"277312274402958520656644106207902100904",
"110393914291342294599159585209415772545",
"280154200158845008732080971928634494447",
"248855276495364183459347879954534493329",
"333581335254214196230916721292571348375",
"114181050096412071044006445671115512524",
"136052348927330063195115664787261563455",
"188087543693707262742725976105528046654",
"15295476098756039603274666119825004787",
"272295022524174711426299918792555940227",
"19079079583241629160865588539590991165",
"292278515537679329957011357021523534090",
"184580164593086055474281600081002729446",
"324418263755741826054861804250855843679",
"179328730552155059392788249476700824133",
"17393682051066236053032480603770806552",
"198202866339123491830706271301446356981"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "drivers/block/xen-blkback/blkback.c"
},
"id": "CVE-2017-10911-b08704d0"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@089bc0143f489bd3a4578bdff5f4ca68fb26f341",
"digest": {
"line_hashes": [
"142322063134886117052908946596880707532",
"143435686460802352833924648897127939384",
"82597094538504242902732602795610849760",
"218388655358307535169144168507537383279",
"54905369314531066581650332933813902387",
"204358402683528398411114280323813984046",
"272924444076269309275159224653443994580",
"168023754448881388958912192937733794555",
"169867158008634425943060924836844572992",
"247859415062290084410663471351263399081",
"306029142437313967009108114783457140141",
"63432034661476884843044362708105871049",
"307250636798363576229473323954204469981",
"90332220988168578411441769648440504347",
"266258113435345882230478941638092441577",
"116053340167482394005541956777166235471",
"243051704307210429975616041486116002199",
"170603268432535588435853637504394984040",
"6336860461853311196588955669238053260",
"332474718160827055609431970582412579835",
"204523629798490960209377841626674630901",
"161803847694486531913545121362171734266",
"50465302456848016958710688466914585821",
"258592467485337422220682326746870034308",
"228004133067868822797210428933329286316",
"274858402846758001544481520944111823530",
"46605890923794652863567476365214169416",
"303661386028565301391447723446277062349",
"288261610298912334419578786279289376054",
"290229254065651776833047426704301151681"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "drivers/block/xen-blkback/common.h"
},
"id": "CVE-2017-10911-d35f68e4"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@089bc0143f489bd3a4578bdff5f4ca68fb26f341",
"digest": {
"function_hash": "200968569455500126772453415063209356660",
"length": 931.0
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "make_response",
"file": "drivers/block/xen-blkback/blkback.c"
},
"id": "CVE-2017-10911-e5bf1ffa"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-10911.json"
[
{
"source": "https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341",
"digest": {
"function_hash": "200968569455500126772453415063209356660",
"length": 931.0
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "make_response",
"file": "drivers/block/xen-blkback/blkback.c"
},
"id": "CVE-2017-10911-2b8e3466"
},
{
"source": "https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341",
"digest": {
"line_hashes": [
"305295687626261053628472062535625123130",
"241527122757668286491981042048444794031",
"29214158053353921995836630380706418143",
"59448085497753006688546955463935321113",
"178059486168661006060467830429192716717",
"73190716207628327542462847775776559268",
"19295807819882618871017299414403253613",
"41640409495128892964422877466409100409",
"135287371340885021688015520453273931549",
"111568502628415160616006692559373372137",
"39608293214316973445192847671650433368",
"277312274402958520656644106207902100904",
"110393914291342294599159585209415772545",
"280154200158845008732080971928634494447",
"248855276495364183459347879954534493329",
"333581335254214196230916721292571348375",
"114181050096412071044006445671115512524",
"136052348927330063195115664787261563455",
"188087543693707262742725976105528046654",
"15295476098756039603274666119825004787",
"272295022524174711426299918792555940227",
"19079079583241629160865588539590991165",
"292278515537679329957011357021523534090",
"184580164593086055474281600081002729446",
"324418263755741826054861804250855843679",
"179328730552155059392788249476700824133",
"17393682051066236053032480603770806552",
"198202866339123491830706271301446356981"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "drivers/block/xen-blkback/blkback.c"
},
"id": "CVE-2017-10911-6af85ce3"
},
{
"source": "https://github.com/torvalds/linux/commit/089bc0143f489bd3a4578bdff5f4ca68fb26f341",
"digest": {
"line_hashes": [
"142322063134886117052908946596880707532",
"143435686460802352833924648897127939384",
"82597094538504242902732602795610849760",
"218388655358307535169144168507537383279",
"54905369314531066581650332933813902387",
"204358402683528398411114280323813984046",
"272924444076269309275159224653443994580",
"168023754448881388958912192937733794555",
"169867158008634425943060924836844572992",
"247859415062290084410663471351263399081",
"306029142437313967009108114783457140141",
"63432034661476884843044362708105871049",
"307250636798363576229473323954204469981",
"90332220988168578411441769648440504347",
"266258113435345882230478941638092441577",
"116053340167482394005541956777166235471",
"243051704307210429975616041486116002199",
"170603268432535588435853637504394984040",
"6336860461853311196588955669238053260",
"332474718160827055609431970582412579835",
"204523629798490960209377841626674630901",
"161803847694486531913545121362171734266",
"50465302456848016958710688466914585821",
"258592467485337422220682326746870034308",
"228004133067868822797210428933329286316",
"274858402846758001544481520944111823530",
"46605890923794652863567476365214169416",
"303661386028565301391447723446277062349",
"288261610298912334419578786279289376054",
"290229254065651776833047426704301151681"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "drivers/block/xen-blkback/common.h"
},
"id": "CVE-2017-10911-c02590ed"
}
]