Input validation error in Xen - CVE-2016-2270
Published: February 19, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32324
CSH Severity: Medium
CVSS v4: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H]
CVE-ID: CVE-2016-2270
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to a crash the entire system.
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
Affected software
Xen
xen (Alpine package)
xen
Fedora
xen (Alpine package)
xen
Fedora
How to mitigate CVE-2016-2270
Install update from vendor's website.
xen (Alpine package) - update to 4.3.4-r2
xen - addressed in versions 4.5.2-8.fc22, 4.5.2-8.fc23
xen - addressed in versions 4.5.2-8.fc22, 4.5.2-8.fc23
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177990.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178518.html
- http://www.debian.org/security/2016/dsa-3519
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securitytracker.com/id/1035042
- http://xenbits.xen.org/xsa/advisory-154.html
- https://security.gentoo.org/glsa/201604-03