CVE-2016-9382
published 2017-01-23CVE-2016-9382: Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.45%
36.5th percentile
Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.8.0-1 (bookworm) | xen 4.8.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6gg6-vw3j-g8pq: Xen 4
ghsa_unreviewed·2022-05-17
CVE-2016-9382 [HIGH] GHSA-6gg6-vw3j-g8pq: Xen 4
Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.
OSV
CVE-2016-9382: Xen 4
osv·2017-01-23·CVSS 7.8
CVE-2016-9382 [HIGH] CVE-2016-9382: Xen 4
Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.
Red Hat
xen: x86 task switch to VM86 mode mis-handled (XSA-192)
vendor_redhat·2016-11-22·CVSS 7.8
CVE-2016-9382 [HIGH] xen: x86 task switch to VM86 mode mis-handled (XSA-192)
xen: x86 task switch to VM86 mode mis-handled (XSA-192)
Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2016-9382: xen - Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows l...
vendor_debian·2016·CVSS 7.8
CVE-2016-9382 [HIGH] CVE-2016-9382: xen - Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows l...
Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.
Scope: local
bookworm: resolved (fixed in 4.8.0-1)
bullseye: resolved (fixed in 4.8.0-1)
forky: resolved (fixed in 4.8.0-1)
sid: resolved (fixed in 4.8.0-1)
trixie: resolved (fixed in 4.8.0-1)
Citrix
Citrix Security Bulletin CTX218775
vendor_citrix·CVSS 7.9
CVE-2016-9379 [HIGH] Citrix Security Bulletin CTX218775
Citrix Security Bulletin CTX218775
CVE References: CVE-2016-9379, CVE-2016-9380, CVE-2016-9381, CVE-2016-9382, CVE-2016-9383, CVE-2016-9385, CVE-2016-9386, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]
bugzilla·2016-11-22·CVSS 5.5
CVE-2016-9377 [MEDIUM] CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]
CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chan
Bugzilla
CVE-2016-9382 xsa192 xen: x86 task switch to VM86 mode mis-handled (XSA-192)
bugzilla·2016-11-08·CVSS 7.8
CVE-2016-9382 [HIGH] CVE-2016-9382 xsa192 xen: x86 task switch to VM86 mode mis-handled (XSA-192)
CVE-2016-9382 xsa192 xen: x86 task switch to VM86 mode mis-handled (XSA-192)
ISSUE DESCRIPTION
LDTR, just like TR, is purely a protected mode facility. Hence even
when switching to a VM86 mode task, LDTR loading needs to follow
protected mode semantics. This was violated by the code.
IMPACT
On SVM (AMD hardware): a malicious unprivileged guest process can
escalate its privilege to that of the guest operating system.
On both SVM and VMX (Intel hardware): a malicious unprivileged guest
process can crash the guest.
VULNERABLE SYSTEMS
Only 32-bit x86 HVM guests are vulnerable. Furthermore, only guest
operating systems which actually make use of hardware task switching,
and allow a new task to start in VM86 mode, are vulnerable. We are
not aware of any such operating systems.
The vulner
http://www.securityfocus.com/bid/94470http://www.securitytracker.com/id/1037341http://xenbits.xen.org/xsa/advisory-192.htmlhttps://security.gentoo.org/glsa/201612-56https://support.citrix.com/article/CTX218775http://www.securityfocus.com/bid/94470http://www.securitytracker.com/id/1037341http://xenbits.xen.org/xsa/advisory-192.htmlhttps://security.gentoo.org/glsa/201612-56https://support.citrix.com/article/CTX218775
2017-01-23
Published