CVE-2016-3159
published 2016-04-13CVE-2016-3159: The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which…
PriorityP412low3.8CVSS 3.0
AVLACLPRLUINSCCLINAN
EPSS
0.40%
32.4th percentile
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | — | — |
| debian | debian_linux | — | — |
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | vm_server | — | — |
| oracle | vm_server | — | — |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | 4.3.0 – 4.3.4 | — |
| xen | xen | 4.4.0 – 4.4.4 | — |
| xen | xen | 4.5.0 – 4.5.3 | — |
| xen | xen | 4.6.0 – 4.6.1 | — |
CVSS provenance
nvdv3.03.8LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_apache9.8MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
vendor_redhat·2016-03-24·CVSS 4.3
CVE-2016-3159 [MEDIUM] xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Statement: This issue does not affect the Xen hypervisor packages as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2016-3159: xen - The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle ...
vendor_debian·2016·CVSS 4.3
CVE-2016-3159 [MEDIUM] CVE-2016-3159: xen - The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle ...
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
Apache
Apache camel: CVE-2017-3159
vendor_apache·CVSS 9.8
CVE-2017-3159 [MEDIUM] Apache camel: CVE-2017-3159
Apache camel: CVE-2017-3159
2.17.0 up to 2.17.4, 2.18.0 up to 2.18.1 2.17.5, 2.18.2 and newer MEDIUM Apache Camel's Snakeyaml unmarshalling operation is vulnerable to Remote Code Execution attacks 2016
Severity: medium
GHSA
GHSA-h55q-7cr6-wwr6: The fpu_fxrstor function in arch/x86/i387
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2016-3159 [MEDIUM] CWE-200 GHSA-h55q-7cr6-wwr6: The fpu_fxrstor function in arch/x86/i387
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
OSV
CVE-2016-3159: The fpu_fxrstor function in arch/x86/i387
osv·2016-04-13·CVSS 4.3
CVE-2016-3159 [MEDIUM] CVE-2016-3159: The fpu_fxrstor function in arch/x86/i387
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
No detection rules found.
No public exploits indexed.
arXiv
DuVisor: a User-level Hypervisor Through Delegated Virtualization
arxiv_fulltext·2022-01-24
DuVisor: a User-level Hypervisor Through Delegated Virtualization
: a User-level Hypervisor Through Delegated Virtualization
Jiahao Chen, Dingji Li, Zeyu MiZeyu Mi ([email protected]) is the corresponding author, Yuxuan Liu,
Binyu Zang, Haibing Guan, Haibo Chen
Institute of Parallel and Distributed Systems, Shanghai Jiao Tong University
empty
## Abstract
Today's mainstream virtualization systems comprise of two cooperative components:
a kernel-resident driver that accesses virtualization hardware and a user-level helper process that
provides VM management and I/O virtualization.
However, this virtualization architecture has intrinsic issues in both security (a large attack surface) and performance.
While there is a long thread of work trying to minimize the kernel-resident driver by offloading functions to user mode,
they face a fundamental trade
Bugzilla
CVE-2016-3158 CVE-2016-3159 xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172) [fedora-all]
bugzilla·2016-03-29·CVSS 3.8
CVE-2016-3158 [LOW] CVE-2016-3158 CVE-2016-3159 xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172) [fedora-all]
CVE-2016-3158 CVE-2016-3159 xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2016-3158 CVE-2016-3159 xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
bugzilla·2016-03-15·CVSS 3.8
CVE-2016-3158 [LOW] CVE-2016-3158 CVE-2016-3159 xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
CVE-2016-3158 CVE-2016-3159 xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
ISSUE DESCRIPTION
There is a workaround in Xen to deal with the fact that AMD CPUs don't
load the x86 registers FIP (and possibly FCS), FDP (and possibly FDS),
and FOP from memory (via XRSTOR or FXRSTOR) when there is no pending
unmasked exception.
However, this workaround does not cover all possible input cases.
This is because writes to the hardware FSW.ES bit, which the current
workaround is based on, are ignored; instead, the CPU calculates
FSW.ES from the pending exception and exception mask bits. Xen
therefore needs to do the same.
Note that part of said workaround was the subject of XSA-52.
IMPACT
A malicious domain may be able to leverage this to obtain sensitive
information such as cryptogr
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181699.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/181729.htmlhttp://support.citrix.com/article/CTX209443http://www.debian.org/security/2016/dsa-3554http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/85716http://www.securitytracker.com/id/1035435http://xenbits.xen.org/xsa/advisory-172.htmlhttp://xenbits.xen.org/xsa/xsa172.patchhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/181699.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/181729.htmlhttp://support.citrix.com/article/CTX209443http://www.debian.org/security/2016/dsa-3554http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/85716http://www.securitytracker.com/id/1035435http://xenbits.xen.org/xsa/advisory-172.htmlhttp://xenbits.xen.org/xsa/xsa172.patch
2016-04-13
Published