CVE-2016-9381
published 2017-01-23CVE-2016-9381: Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch"…
PriorityP335high7.5CVSS 3.1
AVLACHPRHUINSCCHIHAH
EPSS
0.29%
21.4th percentile
Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| qemu | qemu | <= 2.7.1 | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.33 | 2.0.0+dfsg-2ubuntu1.33 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.11 | 1:2.5+dfsg-5ubuntu10.11 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fg67-6qhp-f8mj: Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double
ghsa_unreviewed·2022-05-13
CVE-2016-9381 [HIGH] CWE-362 GHSA-fg67-6qhp-f8mj: Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double
Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.
OSV
qemu vulnerabilities
osv·2017-04-20·CVSS 5.5
CVE-2016-10028 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU
device. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)
Li Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2016-10155)
Li Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet
Controller. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7907)
It was disc
OSV
CVE-2016-9381: Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double
osv·2017-01-23·CVSS 7.5
CVE-2016-9381 [HIGH] CVE-2016-9381: Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double
Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2017-04-20·CVSS 5.5
CVE-2016-10028 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU
device. An attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. This issue only affected Ubuntu
16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)
Li Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A
privileged attacker inside the guest could use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2016-10155)
Li Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet
Controller. A privileged attacker inside the guest could use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ub
Red Hat
xen: qemu incautious about shared ring processing (XSA-197)
vendor_redhat·2016-11-22·CVSS 7.5
CVE-2016-9381 [HIGH] xen: qemu incautious about shared ring processing (XSA-197)
xen: qemu incautious about shared ring processing (XSA-197)
Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affect
Debian
CVE-2016-9381: xen - Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to ga...
vendor_debian·2016·CVSS 7.5
CVE-2016-9381 [HIGH] CVE-2016-9381: xen - Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to ga...
Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
Citrix
Citrix Security Bulletin CTX218775
vendor_citrix·CVSS 7.9
CVE-2016-9379 [HIGH] Citrix Security Bulletin CTX218775
Citrix Security Bulletin CTX218775
CVE References: CVE-2016-9379, CVE-2016-9380, CVE-2016-9381, CVE-2016-9382, CVE-2016-9383, CVE-2016-9385, CVE-2016-9386, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9381 qemu: xsa197 xen: qemu incautious about shared ring processing (XSA-197) [fedora-all]
bugzilla·2016-11-22·CVSS 7.5
CVE-2016-9381 [HIGH] CVE-2016-9381 qemu: xsa197 xen: qemu incautious about shared ring processing (XSA-197) [fedora-all]
CVE-2016-9381 qemu: xsa197 xen: qemu incautious about shared ring processing (XSA-197) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]
bugzilla·2016-11-22·CVSS 5.5
CVE-2016-9377 [MEDIUM] CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]
CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chan
Bugzilla
CVE-2016-9381 xsa197 xen: qemu incautious about shared ring processing (XSA-197)
bugzilla·2016-11-08·CVSS 7.5
CVE-2016-9381 [HIGH] CVE-2016-9381 xsa197 xen: qemu incautious about shared ring processing (XSA-197)
CVE-2016-9381 xsa197 xen: qemu incautious about shared ring processing (XSA-197)
ISSUE DESCRIPTION
The compiler can emit optimizations in qemu which can lead to double
fetch vulnerabilities. Specifically data on the rings shared between
qemu and the hypervisor (which the guest under control can obtain
mappings of) can be fetched twice (during which time the guest can
alter the contents) possibly leading to arbitrary code execution in
qemu.
IMPACT
Malicious administrators can exploit this vulnerability to take over
the qemu process, elevating its privilege to that of the qemu process.
In a system not using a device model stub domain (or other techniques
for deprivileging qemu), malicious guest administrators can thus
elevate their privilege to that of the host.
VULNERABLE SYSTEMS
All
http://www.securityfocus.com/bid/94476http://www.securitytracker.com/id/1037344http://xenbits.xen.org/xsa/advisory-197.htmlhttps://security.gentoo.org/glsa/201612-56https://support.citrix.com/article/CTX218775http://www.securityfocus.com/bid/94476http://www.securitytracker.com/id/1037344http://xenbits.xen.org/xsa/advisory-197.htmlhttps://security.gentoo.org/glsa/201612-56https://support.citrix.com/article/CTX218775
2017-01-23
Published