CVE-2016-2270
published 2016-02-19CVE-2016-2270: Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with…
PriorityP423medium6.8CVSS 3.0
AVNACLPRHUINSCCNINAH
EPSS
1.48%
71.1th percentile
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | vm_server | — | — |
| xen | xen | <= 4.6.1 | — |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:S/C:N/I:N/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xrgf-45jw-vmmp: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2016-2270 [MEDIUM] CWE-20 GHSA-xrgf-45jw-vmmp: Xen 4
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
OSV
CVE-2016-2270: Xen 4
osv·2016-02-19·CVSS 6.8
CVE-2016-2270 [MEDIUM] CVE-2016-2270: Xen 4
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
Red Hat
xen: inconsistent cachability flags on guest mappings (XSA-154)
vendor_redhat·2016-02-17·CVSS 6.8
CVE-2016-2270 [MEDIUM] xen: inconsistent cachability flags on guest mappings (XSA-154)
xen: inconsistent cachability flags on guest mappings (XSA-154)
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-2270: xen - Xen 4.6.x and earlier allows local guest administrators to cause a denial of ser...
vendor_debian·2016·CVSS 6.8
CVE-2016-2270 [MEDIUM] CVE-2016-2270: xen - Xen 4.6.x and earlier allows local guest administrators to cause a denial of ser...
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2270 xsa154 xen: inconsistent cachability flags on guest mappings (XSA-154) [fedora-all]
bugzilla·2016-02-17·CVSS 6.8
CVE-2016-2270 [MEDIUM] CVE-2016-2270 xsa154 xen: inconsistent cachability flags on guest mappings (XSA-154) [fedora-all]
CVE-2016-2270 xsa154 xen: inconsistent cachability flags on guest mappings (XSA-154) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2016-2270 xsa154 xen: inconsistent cachability flags on guest mappings (XSA-154)
bugzilla·2016-02-04·CVSS 6.8
CVE-2016-2270 [MEDIUM] CVE-2016-2270 xsa154 xen: inconsistent cachability flags on guest mappings (XSA-154)
CVE-2016-2270 xsa154 xen: inconsistent cachability flags on guest mappings (XSA-154)
ISSUE DESCRIPTION
Multiple mappings of the same physical page with different cachability setting can cause problems. While one category (risk of using stale data) affects only guests themselves (and hence avoiding this can be left for them to control), the other category being Machine Check exceptions can be fatal to entire hosts. According to the information we were able to gather, only mappings of MMIO pages may surface this second category, but even for them there were cases where the hypervisor did not properly enforce consistent cachability.
IMPACT
A malicious guest administrator might be able to cause a reboot, denying service to the entire host.
VULNERABLE SYSTEMS
Only x86 guests given control
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177990.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-March/178518.htmlhttp://www.debian.org/security/2016/dsa-3519http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securitytracker.com/id/1035042http://xenbits.xen.org/xsa/advisory-154.htmlhttps://security.gentoo.org/glsa/201604-03http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177990.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-March/178518.htmlhttp://www.debian.org/security/2016/dsa-3519http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securitytracker.com/id/1035042http://xenbits.xen.org/xsa/advisory-154.htmlhttps://security.gentoo.org/glsa/201604-03
2016-02-19
Published