Input validation error in Xen - CVE-2016-10024

 

Input validation error in Xen - CVE-2016-10024

Published: January 26, 2017 / Updated: July 28, 2020


Vulnerability identifier: #VU32183
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H]
CVE-ID: CVE-2016-10024
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to a crash the entire system.

Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.


Affected software

Xen
xen (Alpine package)
xen
SUSE Linux
Fedora
Opensuse

How to mitigate CVE-2016-10024

Install update from vendor's website.

xen (Alpine package) - update to 4.6.3-r5
xen - addressed in versions 4.6.4-5.fc24, 4.7.1-6.fc25

External References

Related Security Bulletins