CVE-2016-4962
published 2016-06-07CVE-2016-4962: The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management…
PriorityP426medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.40%
32.2th percentile
The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| oracle | vm_server | — | — |
| oracle | vm_server | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: Unsanitised guest input in libxl device handling code (XSA-175)
vendor_redhat·2016-06-02·CVSS 6.7
CVE-2016-4962 [MEDIUM] xen: Unsanitised guest input in libxl device handling code (XSA-175)
xen: Unsanitised guest input in libxl device handling code (XSA-175)
The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-4962: xen - The libxl device-handling in Xen 4.6.x and earlier allows local OS guest adminis...
vendor_debian·2016·CVSS 6.7
CVE-2016-4962 [MEDIUM] CVE-2016-4962: xen - The libxl device-handling in Xen 4.6.x and earlier allows local OS guest adminis...
The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
GHSA
GHSA-42rm-gcmp-3557: The libxl device-handling in Xen 4
ghsa_unreviewed·2022-05-17
CVE-2016-4962 [MEDIUM] GHSA-42rm-gcmp-3557: The libxl device-handling in Xen 4
The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.
OSV
CVE-2016-4962: The libxl device-handling in Xen 4
osv·2016-06-07·CVSS 6.7
CVE-2016-4962 [MEDIUM] CVE-2016-4962: The libxl device-handling in Xen 4
The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4962 xsa175 xen: Unsanitised guest input in libxl device handling code (XSA-175) [fedora-all]
bugzilla·2016-06-02·CVSS 6.7
CVE-2016-4962 [MEDIUM] CVE-2016-4962 xsa175 xen: Unsanitised guest input in libxl device handling code (XSA-175) [fedora-all]
CVE-2016-4962 xsa175 xen: Unsanitised guest input in libxl device handling code (XSA-175) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2016-4962 xsa175 xen: Unsanitised guest input in libxl device handling code (XSA-175)
bugzilla·2016-05-12·CVSS 6.7
CVE-2016-4962 [MEDIUM] CVE-2016-4962 xsa175 xen: Unsanitised guest input in libxl device handling code (XSA-175)
CVE-2016-4962 xsa175 xen: Unsanitised guest input in libxl device handling code (XSA-175)
ISSUE DESCRIPTION
Various parts of libxl device-handling code inappropriately use
information from (partially) guest controlled areas of xenstore
(principally the frontend directory
/local/domain/GUEST/device/TYPE/DEVID,
henceforth referred to as FE). The problems vary by device type:
For all devices other than the main PV console, the guest can write
FE/backend to point to the backend of a device belonging to a
different guest. On subsequent domain removal (for example, by guest
reboot or migration) libxl uses this value with insufficient checks,
allowing libxl to be tricked into tearing down devices belonging to
other guests.
For almost all device types (all devices except consoles and
channels)
http://www.debian.org/security/2016/dsa-3633http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/91006http://www.securitytracker.com/id/1036023http://xenbits.xen.org/xsa/advisory-175.htmlhttp://www.debian.org/security/2016/dsa-3633http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/91006http://www.securitytracker.com/id/1036023http://xenbits.xen.org/xsa/advisory-175.html
2016-06-07
Published