cbcvebase.
CVE-2016-7154
published 2016-09-21

CVE-2016-7154: Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and…

PriorityP426medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.50%
39.6th percentile
Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianxen< xen 4.6.0-1 (bookworm)xen 4.6.0-1 (bookworm)
xenxen
xenxen
xenxen
xenxen
xenxen
xenxen>= 0 < 4.6.0-14.6.0-1
xenxen>= 0 < 4.6.0-14.6.0-1
xenxen>= 0 < 4.6.0-14.6.0-1
xenxen>= 0 < 4.6.0-14.6.0-1

CVSS provenance

nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.