#VU32217 Input validation error in Xen - CVE-2016-9380
Published: January 23, 2017 / Updated: July 28, 2020
Xen
Xen Project
Description
The vulnerability allows a local authenticated user to read and manipulate data.
The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.