SB2016092138 - Buffer overflow in Xen
Published: September 21, 2016 Updated: July 28, 2020
Security Bulletin ID
SB2016092138
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2016-7094)
The vulnerability allows a local privileged user to perform a denial of service (DoS) attack.
Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update.
Remediation
Install update from vendor's website.
References
- http://support.citrix.com/article/CTX216071
- http://www.debian.org/security/2016/dsa-3663
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/bid/92864
- http://www.securitytracker.com/id/1036753
- http://xenbits.xen.org/xsa/advisory-187.html
- http://xenbits.xen.org/xsa/xsa187-0001-x86-shadow-Avoid-overflowing-sh_ctxt-seg_reg.patch
- https://security.gentoo.org/glsa/201611-09