Permissions, Privileges, and Access Controls in Xen - CVE-2016-10013
Published: January 26, 2017 / Updated: July 28, 2020
Vulnerability identifier: #VU32185
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10013
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.
Affected software
Xen
xen (Alpine package)
xen
SUSE Linux
Fedora
Opensuse
xen (Alpine package)
xen
SUSE Linux
Fedora
Opensuse
How to mitigate CVE-2016-10013
Install update from vendor's website.
xen (Alpine package) - update to 4.6.3-r5
xen - addressed in versions 4.6.4-5.fc24, 4.7.1-6.fc25
xen - addressed in versions 4.6.4-5.fc24, 4.7.1-6.fc25
External References
Related Security Bulletins
- Permissions, Privileges, and Access Controls in Xen
- OpenSUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- SUSE Linux update for xen
- Permissions, Privileges, and Access Controls in xen (Alpine package)
- Fedora 25 update for xen
- Fedora 24 update for xen