CVE-2016-6259
published 2016-08-02CVE-2016-6259: Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local…
PriorityP419medium6.2CVSS 3.0
AVLACLPRNUINSUCNINAH
EPSS
0.64%
46.5th percentile
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
CVSS provenance
nvdv3.06.2MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: x86: Missing SMAP whitelisting in 32-bit exception / event delivery (XSA-183)
vendor_redhat·2016-07-26·CVSS 6.2
CVE-2016-6259 [MEDIUM] xen: x86: Missing SMAP whitelisting in 32-bit exception / event delivery (XSA-183)
xen: x86: Missing SMAP whitelisting in 32-bit exception / event delivery (XSA-183)
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-6259: xen - Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP...
vendor_debian·2016·CVSS 6.2
CVE-2016-6259 [MEDIUM] CVE-2016-6259: xen - Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP...
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
Citrix
Citrix Security Bulletin CTX214954
vendor_citrix·CVSS 8.8
CVE-2016-6258 [HIGH] Citrix Security Bulletin CTX214954
Citrix Security Bulletin CTX214954
CVE References: CVE-2016-6258, CVE-2016-6259, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-prj4-495w-f4qv: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2016-6259 [MEDIUM] CWE-20 GHSA-prj4-495w-f4qv: Xen 4
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
OSV
CVE-2016-6259: Xen 4
osv·2016-08-02·CVSS 6.2
CVE-2016-6259 [MEDIUM] CVE-2016-6259: Xen 4
Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6259 xsa183 xen: x86: Missing SMAP whitelisting in 32-bit exception / event delivery (XSA-183) [fedora-all]
bugzilla·2016-07-26·CVSS 6.2
CVE-2016-6259 [MEDIUM] CVE-2016-6259 xsa183 xen: x86: Missing SMAP whitelisting in 32-bit exception / event delivery (XSA-183) [fedora-all]
CVE-2016-6259 xsa183 xen: x86: Missing SMAP whitelisting in 32-bit exception / event delivery (XSA-183) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2016-6259 xsa183 xen: x86: Missing SMAP whitelisting in 32-bit exception / event delivery (XSA-183)
bugzilla·2016-07-13·CVSS 6.2
CVE-2016-6259 [MEDIUM] CVE-2016-6259 xsa183 xen: x86: Missing SMAP whitelisting in 32-bit exception / event delivery (XSA-183)
CVE-2016-6259 xsa183 xen: x86: Missing SMAP whitelisting in 32-bit exception / event delivery (XSA-183)
ISSUE DESCRIPTION
Supervisor Mode Access Prevention is a hardware feature designed to make
an Operating System more robust, by raising a pagefault rather than
accidentally following a pointer into userspace. However, legitimate
accesses into userspace require whitelisting, and the exception delivery
mechanism for 32bit PV guests wasn't whitelisted.
IMPACT
A malicious 32-bit PV guest kernel can trigger a safety check, crashing
the hypervisor and causing a denial of service to other VMs on the host.
VULNERABLE SYSTEMS
Xen version 4.5 and newer are vulnerable. Versions 4.4 and older are
not, due to not having software support for SMAP.
The vulnerability is only exposed on x86 hardwar
http://support.citrix.com/article/CTX214954http://www.securityfocus.com/bid/92130http://www.securitytracker.com/id/1036447http://xenbits.xen.org/xsa/advisory-183.htmlhttp://xenbits.xen.org/xsa/xsa183-4.6.patchhttp://xenbits.xen.org/xsa/xsa183-unstable.patchhttp://support.citrix.com/article/CTX214954http://www.securityfocus.com/bid/92130http://www.securitytracker.com/id/1036447http://xenbits.xen.org/xsa/advisory-183.htmlhttp://xenbits.xen.org/xsa/xsa183-4.6.patchhttp://xenbits.xen.org/xsa/xsa183-unstable.patch
2016-08-02
Published