CVE-2016-4480
published 2016-05-18CVE-2016-4480: The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4…
PriorityP338high8.4CVSS 3.0
AVLACLPRNUINSUCHIHAH
EPSS
0.54%
41.9th percentile
The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| oracle | vm_server | — | — |
| oracle | vm_server | — | — |
| oracle | vm_server | — | — |
| xen | xen | <= 4.6.1 | — |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
CVSS provenance
nvdv3.08.4HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.4HIGH
vendor_debian8.4HIGH
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: x86 software guest page walk PS bit handling flaw (XSA-176)
vendor_redhat·2016-05-17·CVSS 8.4
CVE-2016-4480 [HIGH] xen: x86 software guest page walk PS bit handling flaw (XSA-176)
xen: x86 software guest page walk PS bit handling flaw (XSA-176)
The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2016-4480: xen - The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earl...
vendor_debian·2016·CVSS 8.4
CVE-2016-4480 [HIGH] CVE-2016-4480: xen - The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earl...
The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
GHSA
GHSA-mrv5-xm7c-h532: The guest_walk_tables function in arch/x86/mm/guest_walk
ghsa_unreviewed·2022-05-17
CVE-2016-4480 [HIGH] GHSA-mrv5-xm7c-h532: The guest_walk_tables function in arch/x86/mm/guest_walk
The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.
OSV
CVE-2016-4480: The guest_walk_tables function in arch/x86/mm/guest_walk
osv·2016-05-18·CVSS 8.4
CVE-2016-4480 [HIGH] CVE-2016-4480: The guest_walk_tables function in arch/x86/mm/guest_walk
The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2016/dsa-3633http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/90710http://www.securitytracker.com/id/1035901http://xenbits.xen.org/xsa/advisory-176.htmlhttp://www.debian.org/security/2016/dsa-3633http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/90710http://www.securitytracker.com/id/1035901http://xenbits.xen.org/xsa/advisory-176.html
2016-05-18
Published