cbcvebase.
CVE-2016-4480
published 2016-05-18

CVE-2016-4480: The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4…

PriorityP338high8.4CVSS 3.0
AVLACLPRNUINSUCHIHAH
EPSS
0.54%
41.9th percentile
The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.8.0~rc3-1 (bookworm)xen 4.8.0~rc3-1 (bookworm)
oraclevm_server
oraclevm_server
oraclevm_server
xenxen<= 4.6.1
xenxen>= 0 < 4.8.0~rc3-14.8.0~rc3-1
xenxen>= 0 < 4.8.0~rc3-14.8.0~rc3-1
xenxen>= 0 < 4.8.0~rc3-14.8.0~rc3-1
xenxen>= 0 < 4.8.0~rc3-14.8.0~rc3-1

CVSS provenance

nvdv3.08.4HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.4HIGH
vendor_debian8.4HIGH
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.