Improper access control in Xen - CVE-2016-9378

 

Improper access control in Xen - CVE-2016-9378

Published: February 22, 2017 / Updated: July 28, 2020


Vulnerability identifier: #VU32221
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9378
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.


Affected software

Xen
xen (Alpine package)
xen
Fedora

How to mitigate CVE-2016-9378

Install update from vendor's website.

xen (Alpine package) - update to 4.5.3-r2
xen - addressed in versions 4.5.5-4.fc23, 4.6.4-2.fc24, 4.7.1-3.fc25

External References

Related Security Bulletins