CVE-2016-4963
published 2016-06-07CVE-2016-4963: The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool…
PriorityP414medium4.7CVSS 3.0
AVLACHPRLUINSUCNINAH
EPSS
0.30%
21.6th percentile
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: Unsanitised driver domain input in libxl device handling (XSA-178)
vendor_redhat·2016-06-02·CVSS 4.7
CVE-2016-4963 [MEDIUM] xen: Unsanitised driver domain input in libxl device handling (XSA-178)
xen: Unsanitised driver domain input in libxl device handling (XSA-178)
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-4963: xen - The libxl device-handling in Xen through 4.6.x allows local guest OS users with ...
vendor_debian·2016·CVSS 4.7
CVE-2016-4963 [MEDIUM] CVE-2016-4963: xen - The libxl device-handling in Xen through 4.6.x allows local guest OS users with ...
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
GHSA
GHSA-4wh7-gxf5-7gc2: The libxl device-handling in Xen through 4
ghsa_unreviewed·2022-05-14
CVE-2016-4963 [MEDIUM] CWE-284 GHSA-4wh7-gxf5-7gc2: The libxl device-handling in Xen through 4
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore.
OSV
CVE-2016-4963: The libxl device-handling in Xen through 4
osv·2016-06-07·CVSS 4.7
CVE-2016-4963 [MEDIUM] CVE-2016-4963: The libxl device-handling in Xen through 4
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4963 xsa178 xen: Unsanitised driver domain input in libxl device handling (XSA-178) [fedora-all]
bugzilla·2016-06-02·CVSS 4.7
CVE-2016-4963 [MEDIUM] CVE-2016-4963 xsa178 xen: Unsanitised driver domain input in libxl device handling (XSA-178) [fedora-all]
CVE-2016-4963 xsa178 xen: Unsanitised driver domain input in libxl device handling (XSA-178) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2016-4963 xsa178 xen: Unsanitised driver domain input in libxl device handling (XSA-178)
bugzilla·2016-05-12·CVSS 4.7
CVE-2016-4963 [MEDIUM] CVE-2016-4963 xsa178 xen: Unsanitised driver domain input in libxl device handling (XSA-178)
CVE-2016-4963 xsa178 xen: Unsanitised driver domain input in libxl device handling (XSA-178)
ISSUE DESCRIPTION
libxl's device-handling code freely uses and trusts information from
the backend directories in xenstore.
The backend domain (driver domain) can store bogus data in the
backend, causing libxl's enquiry functions to fail, confusing
management tools.
A driver domain can also remove its backend directory from xenstore
entirely, preventing the device from showing up in device listings and
preventing it from being removed and replaced.
A driver domain can cause libxl to generate disk eject events for
disks for which the driver domain is not responsible.
IMPACT
A malicious driver domain can deny service to management tools.
VULNERABLE SYSTEMS
This vulnerability is only applicab
http://www.securitytracker.com/id/1036024http://xenbits.xen.org/xsa/advisory-178.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00006.htmlhttp://www.securitytracker.com/id/1036024http://xenbits.xen.org/xsa/advisory-178.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00006.html
2016-06-07
Published