Improper access control in Xen - CVE-2016-9378
Published: February 22, 2017 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.
Affected software
xen (Alpine package)
xen
Fedora
How to mitigate CVE-2016-9378
xen - addressed in versions 4.5.5-4.fc23, 4.6.4-2.fc24, 4.7.1-3.fc25