CVE Vulnerabilities

CVE-2016-9386

Published: Jan 23, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving unexpected base/limit values.

Affected Software

NameVendorStart VersionEnd Version
XenserverCitrix6.0.2 (including)6.0.2 (including)
XenserverCitrix6.2.0 (including)6.2.0 (including)
XenserverCitrix6.5 (including)6.5 (including)
XenserverCitrix7.0 (including)7.0 (including)
XenUbuntudevel*
XenUbuntuesm-infra/xenial*
XenUbuntuprecise*
XenUbuntutrusty*
XenUbuntuupstream*
XenUbuntuxenial*
XenUbuntuyakkety*
XenUbuntuzesty*

References