High severity8.8NVD Advisory· Published Sep 12, 2017· Updated May 13, 2026
CVE-2017-14316
CVE-2017-14316
Description
A parameter verification issue was discovered in Xen through 4.9.x. The function alloc_heap_pages allows callers to specify the first NUMA node that should be used for allocations through the memflags parameter; the node is extracted using the MEMF_get_node macro. While the function checks to see if the special constant NUMA_NO_NODE is specified, it otherwise does not handle the case where node >= MAX_NUMNODES. This allows an out-of-bounds access to an internal array.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- xenbits.xen.org/xsa/advisory-231.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/100818nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039348nvdThird Party AdvisoryVDB Entry
- lists.debian.org/debian-lts-announce/2018/10/msg00009.htmlnvd
- support.citrix.com/article/CTX227185nvd
- www.debian.org/security/2017/dsa-4050nvd
News mentions
0No linked articles in our index yet.