Information disclosure in Oracle VM Server for x86 and Xen - CVE-2016-7777

 

Information disclosure in Oracle VM Server for x86 and Xen - CVE-2016-7777

Published: October 5, 2016 / Updated: January 10, 2017


Vulnerability identifier: #VU766
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7777
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local unprivileged user to obtain potentially sensitive information on the guest system.
The weakness is caused by insufficient access control mechanisms. A local unprivileged user of a guest operating system can trigger the Xen instruction emulator by attempting to execute an invalid opcode and read or modify FPU, MMX, and XMM register state data of another process within the same guest system.
Successful exploitation of the vulnerability leads to register state information disclosure and corruption.

Affected software

Oracle VM Server for x86
Xen
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
Python 3 Module
openSUSE Leap
xen (Alpine package)
libpython3_11-1_0-32bit-debuginfo
libpython3_11-1_0-debuginfo
python311-dbm-debuginfo
python311-curses-debuginfo
python311-testsuite
python311-testsuite-debuginfo
python311-base-32bit-debuginfo
python311-base-32bit
libpython3_11-1_0-32bit
python311-tools
python311-32bit
python311-32bit-debuginfo
libpython3_11-1_0-64bit-debuginfo
python311-64bit
python311-base-64bit
python311-64bit-debuginfo
python311-base-64bit-debuginfo
libpython3_11-1_0-64bit
python311-tk-debuginfo
python311
libpython3_11-1_0
python311-base
python311-idle
python311-base-debuginfo
python311-devel
python311-core-debugsource
python311-curses
python311-doc-devhelp
python311-debuginfo
python311-dbm
python311-doc
python311-tk
python311-debugsource

How to mitigate CVE-2016-7777

Update to version 5 or apply the following patches:

XSA-190 version 4.5.
http://xenbits.xen.org/xsa/xsa190-4.5.patch
XSA-190 version 4.6.
http://xenbits.xen.org/xsa/xsa190-4.6.patch

xen (Alpine package) - update to 4.5.3-r2
libpython3_11-1_0-32bit-debuginfo - update to 3.11.9-150400.9.29.1
libpython3_11-1_0-debuginfo - update to 3.11.9-150400.9.29.1
python311-dbm-debuginfo - update to 3.11.9-150400.9.29.1
python311-curses-debuginfo - update to 3.11.9-150400.9.29.1
python311-testsuite - update to 3.11.9-150400.9.29.1
python311-testsuite-debuginfo - update to 3.11.9-150400.9.29.1
python311-base-32bit-debuginfo - update to 3.11.9-150400.9.29.1
python311-base-32bit - update to 3.11.9-150400.9.29.1
libpython3_11-1_0-32bit - update to 3.11.9-150400.9.29.1
python311-tools - update to 3.11.9-150400.9.29.1
python311-32bit - update to 3.11.9-150400.9.29.1
python311-32bit-debuginfo - update to 3.11.9-150400.9.29.1
libpython3_11-1_0-64bit-debuginfo - update to 3.11.9-150400.9.29.1
python311-64bit - update to 3.11.9-150400.9.29.1
python311-base-64bit - update to 3.11.9-150400.9.29.1
python311-64bit-debuginfo - update to 3.11.9-150400.9.29.1
python311-base-64bit-debuginfo - update to 3.11.9-150400.9.29.1
libpython3_11-1_0-64bit - update to 3.11.9-150400.9.29.1
python311-tk-debuginfo - update to 3.11.9-150400.9.29.1
python311 - update to 3.11.9-150400.9.29.1
libpython3_11-1_0 - update to 3.11.9-150400.9.29.1
python311-base - update to 3.11.9-150400.9.29.1
python311-idle - update to 3.11.9-150400.9.29.1
python311-base-debuginfo - update to 3.11.9-150400.9.29.1
python311-devel - update to 3.11.9-150400.9.29.1
python311-core-debugsource - update to 3.11.9-150400.9.29.1
python311-curses - update to 3.11.9-150400.9.29.1
python311-doc-devhelp - update to 3.11.9-150400.9.29.1
python311-debuginfo - update to 3.11.9-150400.9.29.1
python311-dbm - update to 3.11.9-150400.9.29.1
python311-doc - update to 3.11.9-150400.9.29.1
python311-tk - update to 3.11.9-150400.9.29.1
python311-debugsource - update to 3.11.9-150400.9.29.1

External References

Related Security Bulletins