CVE Vulnerabilities

CVE-2016-10025

NULL Pointer Dereference

Published: Jan 26, 2017 | Modified: Jan 27, 2017
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging a missing NULL pointer check.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Xen Xen 4.6.0 (including) 4.6.0 (including)
Xen Xen 4.6.1 (including) 4.6.1 (including)
Xen Xen 4.6.3 (including) 4.6.3 (including)
Xen Xen 4.6.4 (including) 4.6.4 (including)
Xen Xen 4.7.0 (including) 4.7.0 (including)
Xen Xen 4.7.1 (including) 4.7.1 (including)
Xen Xen 4.8.0 (including) 4.8.0 (including)

Potential Mitigations

References