Input validation error in Xen - CVE-2016-9380
Published: January 23, 2017 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a local authenticated user to read and manipulate data.
The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.
Affected software
xen (Alpine package)
xen
Fedora
How to mitigate CVE-2016-9380
xen - addressed in versions 4.5.5-4.fc23, 4.6.4-2.fc24, 4.7.1-3.fc25