CVE-2016-9386

Name
CVE-2016-9386
Description
The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory http://www.securityfocus.com/bid/94471
Third Party Advisory http://www.securitytracker.com/id/1037340
Patch http://xenbits.xen.org/xsa/advisory-191.html
cve@mitre.org https://security.gentoo.org/glsa/201612-56
Patch https://support.citrix.com/article/CTX218775

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:citrix:xenserver:6.0.2:*:*:*:*:*:*:* xenserver == None == 6.0.2
cpe:2.3:a:citrix:xenserver:6.2.0:*:*:*:*:*:*:* xenserver == None == 6.2.0
cpe:2.3:a:citrix:xenserver:6.5:*:*:*:*:*:*:* xenserver == None == 6.5
cpe:2.3:a:citrix:xenserver:7.0:*:*:*:*:*:*:* xenserver == None == 7.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
xen edge-main 4.7.1-r1 None fixed
xen 3.22-main 4.7.1-r1 None fixed
xen 3.21-main 4.7.1-r1 None fixed
xen 3.20-main 4.7.1-r1 None fixed
xen 3.19-main 4.7.1-r1 None fixed
xen 3.18-main 4.7.1-r1 None fixed
xen 3.17-main 4.7.1-r1 None fixed
xen 3.12-main 4.7.1-r1 None fixed
xen 3.11-main 4.7.1-r1 None fixed
xen 3.10-main 4.7.1-r1 None fixed