#VU32261 Input validation error in Xen - CVE-2016-6259
Published: August 2, 2016 / Updated: July 28, 2020
Xen
Xen Project
Description
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.