CVE-2016-7154Use After Free in XEN

CWE-416Use After Free6 documents6 sources
Severity
6.7MEDIUMNVD
EPSS
0.1%
top 72.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 21
Latest updateMay 17

Description

Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages3 packages

debiandebian/xen< xen 4.6.0-1 (bookworm)
Debianxen/xen< 4.6.0-1+3
NVDxen/xen5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6m92-fjpm-vf6h: Use-after-free vulnerability in the FIFO event channel code in Xen 42022-05-17
OSV
CVE-2016-7154: Use-after-free vulnerability in the FIFO event channel code in Xen 42016-09-21

📋Vendor Advisories

2
Red Hat
xen: use after free in FIFO event channel code2016-09-08
Debian
CVE-2016-7154: xen - Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows ...2016

💬Community

1
Bugzilla
CVE-2016-7154 xen: use after free in FIFO event channel code2016-09-08