Privilege escalation in Xen - CVE-2016-7092
Published: September 9, 2016 / Updated: March 26, 2018
Vulnerability identifier: #VU388
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7092
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows local administrative user to get elevated privileges on the host system.
The vulnerability exists due to entrying of L3 code in 64-bit hypervisor by administrative user of 32-bit PV that allows him to gain privileges on the target system.
Successful exploitation of this vulnerability will result in gaining elevated privileges by the guest attacker.
The vulnerability exists due to entrying of L3 code in 64-bit hypervisor by administrative user of 32-bit PV that allows him to gain privileges on the target system.
Successful exploitation of this vulnerability will result in gaining elevated privileges by the guest attacker.
Affected software
Xen
Gentoo Linux
SUSE Linux
Fedora
xen (Alpine package)
xen
IBM Systems Director
Gentoo Linux
SUSE Linux
Fedora
xen (Alpine package)
xen
IBM Systems Director
How to mitigate CVE-2016-7092
xen (Alpine package) - addressed in versions 4.4.4-r1, 4.5.3-r1, 4.6.3-r2
xen - addressed in versions 4.5.3-10.fc23, 4.6.3-5.fc24, 4.7.0-5.fc25
xen - addressed in versions 4.5.3-10.fc23, 4.6.3-5.fc24, 4.7.0-5.fc25