CVE-2016-7777
published 2016-10-07CVE-2016-7777: Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state…
PriorityP431medium6.3CVSS 3.0
AVLACHPRLUINSUCHIHAN
EPSS
0.30%
22.5th percentile
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| xen | xen | <= 4.7.0 | — |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
| xen | xen | >= 0 < 4.8.0~rc3-1 | 4.8.0~rc3-1 |
CVSS provenance
nvdv3.06.3MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cr4c-368c-2fc2: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2016-7777 [MEDIUM] CWE-362 GHSA-cr4c-368c-2fc2: Xen 4
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.
OSV
CVE-2016-7777: Xen 4
osv·2016-10-07·CVSS 6.3
CVE-2016-7777 [MEDIUM] CVE-2016-7777: Xen 4
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.
Red Hat
xen: CR0.TS and CR0.EM not always honored for x86 HVM guests (XSA-190)
vendor_redhat·2016-10-04·CVSS 6.3
CVE-2016-7777 [MEDIUM] xen: CR0.TS and CR0.EM not always honored for x86 HVM guests (XSA-190)
xen: CR0.TS and CR0.EM not always honored for x86 HVM guests (XSA-190)
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-7777: xen - Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows lo...
vendor_debian·2016·CVSS 6.3
CVE-2016-7777 [MEDIUM] CVE-2016-7777: xen - Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows lo...
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7777 xsa190 xen: CR0.TS and CR0.EM not always honored for x86 HVM guests (XSA-190) [fedora-all]
bugzilla·2016-10-04·CVSS 6.3
CVE-2016-7777 [MEDIUM] CVE-2016-7777 xsa190 xen: CR0.TS and CR0.EM not always honored for x86 HVM guests (XSA-190) [fedora-all]
CVE-2016-7777 xsa190 xen: CR0.TS and CR0.EM not always honored for x86 HVM guests (XSA-190) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2016-7777 xsa190 xen: CR0.TS and CR0.EM not always honored for x86 HVM guests (XSA-190)
bugzilla·2016-09-20·CVSS 6.3
CVE-2016-7777 [MEDIUM] CVE-2016-7777 xsa190 xen: CR0.TS and CR0.EM not always honored for x86 HVM guests (XSA-190)
CVE-2016-7777 xsa190 xen: CR0.TS and CR0.EM not always honored for x86 HVM guests (XSA-190)
ISSUE DESCRIPTION
Instructions touching FPU, MMX, or XMM registers are required to raise
a Device Not Available Exception (#NM) when either CR0.EM or CR0.TS are
set. (Their AVX or AVX-512 extensions would consider only CR0.TS.)
While during normal operation this is ensured by the hardware, if a
guest modifies instructions while the hypervisor is preparing to
emulate them, the #NM delivery could be missed.
Guest code in one task may thus (unintentionally or maliciously) read
or modify register state belonging to another task in the same VM.
IMPACT
A malicious unprivileged guest user may be able to obtain or corrupt
sensitive information (including cryptographic material) in other
programs in the
http://www.securityfocus.com/bid/93344http://www.securitytracker.com/id/1036942http://xenbits.xen.org/xsa/advisory-190.htmlhttps://security.gentoo.org/glsa/201611-09https://support.citrix.com/article/CTX217363http://www.securityfocus.com/bid/93344http://www.securitytracker.com/id/1036942http://xenbits.xen.org/xsa/advisory-190.htmlhttps://security.gentoo.org/glsa/201611-09https://support.citrix.com/article/CTX217363
2016-10-07
Published