CVE-2016-6258
published 2016-08-02CVE-2016-6258: The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging…
PriorityP343high8.8CVSS 3.0
AVLACLPRLUINSCCHIHAH
EPSS
0.40%
32.3th percentile
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: x86: Privilege escalation in PV guests (XSA-182)
vendor_redhat·2016-07-26·CVSS 8.8
CVE-2016-6258 [HIGH] xen: x86: Privilege escalation in PV guests (XSA-182)
xen: x86: Privilege escalation in PV guests (XSA-182)
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
A vulnerability was found Xen's MMU emulation for x86 PV guests. A malicious administrator of an x86 PV guest could control some of the page table bits, allowing potential control of memory and code execution in the host. x86 HVM and ARM guests could not exploit this flaw.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-6258: xen - The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-...
vendor_debian·2016·CVSS 8.8
CVE-2016-6258 [HIGH] CVE-2016-6258: xen - The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-...
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
Citrix
Citrix Security Bulletin CTX214954
vendor_citrix·CVSS 8.8
CVE-2016-6258 [HIGH] Citrix Security Bulletin CTX214954
Citrix Security Bulletin CTX214954
CVE References: CVE-2016-6258, CVE-2016-6259, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-gh95-4f96-964p: The PV pagetable code in arch/x86/mm
ghsa_unreviewed·2022-05-17
CVE-2016-6258 [HIGH] CWE-284 GHSA-gh95-4f96-964p: The PV pagetable code in arch/x86/mm
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
OSV
CVE-2016-6258: The PV pagetable code in arch/x86/mm
osv·2016-08-02·CVSS 8.8
CVE-2016-6258 [HIGH] CVE-2016-6258: The PV pagetable code in arch/x86/mm
The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6258 xsa182 xen: x86: Privilege escalation in PV guests (XSA-182) [fedora-all]
bugzilla·2016-07-26·CVSS 8.8
CVE-2016-6258 [HIGH] CVE-2016-6258 xsa182 xen: x86: Privilege escalation in PV guests (XSA-182) [fedora-all]
CVE-2016-6258 xsa182 xen: x86: Privilege escalation in PV guests (XSA-182) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2016-6258 xsa182 xen: x86: Privilege escalation in PV guests (XSA-182)
bugzilla·2016-07-13·CVSS 8.8
CVE-2016-6258 [HIGH] CVE-2016-6258 xsa182 xen: x86: Privilege escalation in PV guests (XSA-182)
CVE-2016-6258 xsa182 xen: x86: Privilege escalation in PV guests (XSA-182)
ISSUE DESCRIPTION
The PV pagetable code has fast-paths for making updates to pre-existing
pagetable entries, to skip expensive re-validation in safe cases
(e.g. clearing only Access/Dirty bits). The bits considered safe were too
broad, and not actually safe.
IMPACT
A malicous PV guest administrator can escalate their privilege to that
of the host.
VULNERABLE SYSTEMS
All versions of Xen are vulnerable.
The vulnerability is only exposed to PV guests on x86 hardware.
The vulnerability is not exposed to x86 HVM guests, or ARM guests.
MITIGATION
Running only HVM guests will avoid this vulnerability.
External References:
http://xenbits.xen.org/xsa/advisory-182.html
Acknowledgements:
Name: the Xen project
D
http://support.citrix.com/article/CTX214954http://www.debian.org/security/2016/dsa-3633http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/92131http://www.securitytracker.com/id/1036446http://xenbits.xen.org/xsa/advisory-182.htmlhttp://xenbits.xen.org/xsa/xsa182-4.5.patchhttp://xenbits.xen.org/xsa/xsa182-4.6.patchhttp://xenbits.xen.org/xsa/xsa182-unstable.patchhttps://security.gentoo.org/glsa/201611-09http://support.citrix.com/article/CTX214954http://www.debian.org/security/2016/dsa-3633http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/92131http://www.securitytracker.com/id/1036446http://xenbits.xen.org/xsa/advisory-182.htmlhttp://xenbits.xen.org/xsa/xsa182-4.5.patchhttp://xenbits.xen.org/xsa/xsa182-4.6.patchhttp://xenbits.xen.org/xsa/xsa182-unstable.patchhttps://security.gentoo.org/glsa/201611-09
2016-08-02
Published