Permissions, Privileges, and Access Controls in Xen - CVE-2016-9386
Published: January 23, 2017 / Updated: July 28, 2020
Vulnerability identifier: #VU32214
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9386
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.
Affected software
Xen
xen (Alpine package)
xen
Fedora
xen (Alpine package)
xen
Fedora
How to mitigate CVE-2016-9386
Install update from vendor's website.
xen (Alpine package) - update to 4.5.3-r2
xen - addressed in versions 4.5.5-4.fc23, 4.6.4-2.fc24, 4.7.1-3.fc25
xen - addressed in versions 4.5.5-4.fc23, 4.6.4-2.fc24, 4.7.1-3.fc25