CVE-2016-9382Citrix Xenserver vulnerability

CWE-2648 documents7 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 68.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 23
Latest updateMay 17

Description

Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianxen/xen< 4.8.0-1+3
NVDxen/xen39 versions+38
NVDcitrix/xenserver4 versions+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6gg6-vw3j-g8pq: Xen 42022-05-17
OSV
CVE-2016-9382: Xen 42017-01-23
CVEList
CVE-2016-9382: Xen 42017-01-23

📋Vendor Advisories

2
Red Hat
xen: x86 task switch to VM86 mode mis-handled (XSA-192)2016-11-22
Debian
CVE-2016-9382: xen - Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows l...2016

💬Community

2
Bugzilla
CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]2016-11-22
Bugzilla
CVE-2016-9382 xsa192 xen: x86 task switch to VM86 mode mis-handled (XSA-192)2016-11-08
CVE-2016-9382 — Citrix Xenserver vulnerability | cvebase