FlawAtlas
Search the atlas
UBUNTU-CVE-2017-10911 Moderate

UBUNTU-CVE-2017-10911

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.

Exploit probability Not scored
Published July 4, 2017
Required by Not available
Last source change August 17, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS linux

122 explicit affected versions

Ubuntu:14.04:LTS linux-lts-xenial

40 explicit affected versions

Ubuntu:14.04:LTS qemu

58 explicit affected versions

Ubuntu:16.04:LTS linux

62 explicit affected versions

Ubuntu:16.04:LTS linux-aws

21 explicit affected versions

Ubuntu:16.04:LTS linux-gcp

3 explicit affected versions

Ubuntu:16.04:LTS linux-gke

18 explicit affected versions

Ubuntu:16.04:LTS linux-hwe

26 explicit affected versions

Ubuntu:16.04:LTS linux-kvm

3 explicit affected versions

Ubuntu:16.04:LTS linux-raspi2

38 explicit affected versions

Ubuntu:16.04:LTS linux-snapdragon

35 explicit affected versions

Ubuntu:16.04:LTS qemu

29 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iot-realtime

1 explicit affected versions

Ubuntu:22.04:LTS linux-realtime

1 explicit affected versions

Ubuntu:24.04:LTS linux-azure-6.11

7 explicit affected versions

Ubuntu:24.04:LTS linux-gcp-6.11

7 explicit affected versions

Ubuntu:24.04:LTS linux-hwe-6.11

8 explicit affected versions

Ubuntu:24.04:LTS linux-lowlatency-hwe-6.11

7 explicit affected versions

Ubuntu:24.04:LTS linux-raspi-realtime

1 explicit affected versions

Ubuntu:Pro:20.04:LTS linux-azure-fde-5.15

61 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-3468-1
related USN-3470-2

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2017-10911

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.

View original source

05 / REFERENCES

Further evidence