cbcvebase.
CVE-2016-10024
published 2017-01-26

CVE-2016-10024: Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream…

medium6CVSS 3.0
AVLACLPRHUINSCCNINAH
Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.

Affected

17 ranges
VendorProductVersion rangeFixed in
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debianxen< xen 4.8.0-1 (bookworm)xen 4.8.0-1 (bookworm)
xenxen<= 4.8.0
xenxen>= 0 < 4.8.0-14.8.0-1
xenxen>= 0 < 4.8.0-14.8.0-1
xenxen>= 0 < 4.8.0-14.8.0-1
xenxen>= 0 < 4.8.0-14.8.0-1

CVSS provenance

nvdv3.06.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
osv6.0MEDIUM