Input validation error in Xen - CVE-2016-9383

 

Input validation error in Xen - CVE-2016-9383

Published: January 23, 2017 / Updated: July 28, 2020


Vulnerability identifier: #VU32219
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2016-9383
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute arbitrary code on the host by leveraging broken emulation of bit test instructions.


Affected software

Xen
xen (Alpine package)
xen
Fedora

How to mitigate CVE-2016-9383

Install update from vendor's website.

xen (Alpine package) - update to 4.5.3-r2
xen - addressed in versions 4.5.5-4.fc23, 4.6.4-2.fc24, 4.7.1-3.fc25

External References

Related Security Bulletins