|
|
Log in / Subscribe / Register

xen: privilege escalation

Package(s):xen CVE #(s):CVE-2016-7093
Created:September 14, 2016 Updated:September 14, 2016
Description: From the Red Hat bugzilla:

When emulating HVM instructions, Xen uses a small i-cache for fetches from guest memory. The code that handles cache misses does not check if the address from which it fetched lies within the cache before blindly writing to it. As such it is possible for the guest to overwrite hypervisor memory.

It is currently believed that the only way to trigger this bug is to use the way that Xen currently incorrectly wraps CS:IP in 16 bit modes. The included patch prevents such wrapping.

A malicious HVM guest administrator can escalate their privilege to that of the host.

Alerts:
Gentoo 201611-09 xen 2016-11-15
SUSE SUSE-SU-2016:2533-1 xen 2016-10-13
SUSE SUSE-SU-2016:2507-1 xen 2016-10-12
openSUSE openSUSE-SU-2016:2497-1 xen 2016-10-11
openSUSE openSUSE-SU-2016:2494-1 xen 2016-10-11
SUSE SUSE-SU-2016:2473-1 xen 2016-10-07
Fedora FEDORA-2016-1c3374bcb9 xen 2016-09-21
Fedora FEDORA-2016-7d2c67d1f5 xen 2016-09-13
Mageia MGASA-2017-0012 xen 2017-01-09

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds