Input validation error in Xen - CVE-2016-9383
Published: January 23, 2017 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute arbitrary code on the host by leveraging broken emulation of bit test instructions.
Affected software
xen (Alpine package)
xen
Fedora
How to mitigate CVE-2016-9383
xen - addressed in versions 4.5.5-4.fc23, 4.6.4-2.fc24, 4.7.1-3.fc25