Input validation error in Xen - CVE-2016-10024
Published: January 26, 2017 / Updated: July 28, 2020
Vulnerability identifier: #VU32183
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H]
CVE-ID: CVE-2016-10024
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged user to a crash the entire system.
Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.
Affected software
Xen
xen (Alpine package)
xen
SUSE Linux
Fedora
Opensuse
xen (Alpine package)
xen
SUSE Linux
Fedora
Opensuse
How to mitigate CVE-2016-10024
Install update from vendor's website.
xen (Alpine package) - update to 4.6.3-r5
xen - addressed in versions 4.6.4-5.fc24, 4.7.1-6.fc25
xen - addressed in versions 4.6.4-5.fc24, 4.7.1-6.fc25