CVE-2016-1571
published 2016-01-22CVE-2016-1571: The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows…
PriorityP428medium6.3CVSS 3.0
AVNACHPRLUINSCCNINAH
EPSS
1.28%
66.7th percentile
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | <= 6.5 | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: Intercept issue with INVLPG on non-canonical address causing host to crash
vendor_redhat·2016-01-20·CVSS 6.3
CVE-2016-1571 [MEDIUM] xen: Intercept issue with INVLPG on non-canonical address causing host to crash
xen: Intercept issue with INVLPG on non-canonical address causing host to crash
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-1571: xen - The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6....
vendor_debian·2016·CVSS 6.3
CVE-2016-1571 [MEDIUM] CVE-2016-1571: xen - The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6....
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
Citrix
Citrix Security Bulletin CTX205496
vendor_citrix·CVSS 6.3
CVE-2016-1571 [MEDIUM] Citrix Security Bulletin CTX205496
Citrix Security Bulletin CTX205496
CVE References: CVE-2016-1571, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-rh8h-9p3w-xjvv: The paging_invlpg function in include/asm-x86/paging
ghsa_unreviewed·2022-05-14
CVE-2016-1571 [MEDIUM] GHSA-rh8h-9p3w-xjvv: The paging_invlpg function in include/asm-x86/paging
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
OSV
CVE-2016-1571: The paging_invlpg function in include/asm-x86/paging
osv·2016-01-22·CVSS 6.3
CVE-2016-1571 [MEDIUM] CVE-2016-1571: The paging_invlpg function in include/asm-x86/paging
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1571 xen: Intercept issue with INVLPG on non-canonical address causing host to crash [fedora-all]
bugzilla·2016-01-20·CVSS 6.3
CVE-2016-1571 [MEDIUM] CVE-2016-1571 xen: Intercept issue with INVLPG on non-canonical address causing host to crash [fedora-all]
CVE-2016-1571 xen: Intercept issue with INVLPG on non-canonical address causing host to crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2016-1571 xen: Intercept issue with INVLPG on non-canonical address causing host to crash
bugzilla·2016-01-07·CVSS 6.3
CVE-2016-1571 [MEDIUM] CVE-2016-1571 xen: Intercept issue with INVLPG on non-canonical address causing host to crash
CVE-2016-1571 xen: Intercept issue with INVLPG on non-canonical address causing host to crash
ISSUE DESCRIPTION
While INVLPG does not cause a General Protection Fault when used on a non-canonical address, INVVPID in its "individual address" variant, which is used to back the intercepted INVLPG in certain cases, fails in such cases. Failure of INVVPID results in a hypervisor bug check.
IMPACT
A malicious guest can crash the host, leading to a Denial of Service.
VULNERABLE SYSTEMS
Xen versions from 3.3 onwards are affected. Only systems using Intel or Cyrix CPUs are affected. ARM and AMD systems are unaffected. Only HVM guests using shadow mode paging can expose this vulnerability. PV guests, and HVM guests using Hardware Assisted Paging (also known as EPT on affected hardware), are un
http://support.citrix.com/article/CTX205496http://www.debian.org/security/2016/dsa-3519http://www.securitytracker.com/id/1034745http://xenbits.xen.org/xsa/advisory-168.htmlhttp://support.citrix.com/article/CTX205496http://www.debian.org/security/2016/dsa-3519http://www.securitytracker.com/id/1034745http://xenbits.xen.org/xsa/advisory-168.html
2016-01-22
Published