CVE-2016-9385
published 2017-01-23CVE-2016-9385: The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host…
PriorityP419medium6CVSS 3.0
AVLACLPRHUINSCCNINAH
EPSS
0.43%
35.0th percentile
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.8.0-1 (bookworm) | xen 4.8.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv3.06.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3fqp-fm32-6g9x: The x86 segment base write emulation functionality in Xen 4
ghsa_unreviewed·2022-05-17
CVE-2016-9385 [MEDIUM] CWE-20 GHSA-3fqp-fm32-6g9x: The x86 segment base write emulation functionality in Xen 4
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
OSV
CVE-2016-9385: The x86 segment base write emulation functionality in Xen 4
osv·2017-01-23·CVSS 6.0
CVE-2016-9385 [MEDIUM] CVE-2016-9385: The x86 segment base write emulation functionality in Xen 4
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
Red Hat
xen: x86 segment base write emulation lacking canonical address checks (XSA-193)
vendor_redhat·2016-11-22·CVSS 6.0
CVE-2016-9385 [MEDIUM] xen: x86 segment base write emulation lacking canonical address checks (XSA-193)
xen: x86 segment base write emulation lacking canonical address checks (XSA-193)
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2016-9385: xen - The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x al...
vendor_debian·2016·CVSS 6.0
CVE-2016-9385 [MEDIUM] CVE-2016-9385: xen - The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x al...
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
Scope: local
bookworm: resolved (fixed in 4.8.0-1)
bullseye: resolved (fixed in 4.8.0-1)
forky: resolved (fixed in 4.8.0-1)
sid: resolved (fixed in 4.8.0-1)
trixie: resolved (fixed in 4.8.0-1)
Citrix
Citrix Security Bulletin CTX218775
vendor_citrix·CVSS 7.9
CVE-2016-9379 [HIGH] Citrix Security Bulletin CTX218775
Citrix Security Bulletin CTX218775
CVE References: CVE-2016-9379, CVE-2016-9380, CVE-2016-9381, CVE-2016-9382, CVE-2016-9383, CVE-2016-9385, CVE-2016-9386, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]
bugzilla·2016-11-22·CVSS 5.5
CVE-2016-9377 [MEDIUM] CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]
CVE-2016-9377 CVE-2016-9378 CVE-2016-9379 CVE-2016-9380 CVE-2016-9381 CVE-2016-9382 CVE-2016-9383 CVE-2016-9384 CVE-2016-9385 CVE-2016-9386 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chan
Bugzilla
CVE-2016-9385 xsa193 xen: x86 segment base write emulation lacking canonical address checks (XSA-193)
bugzilla·2016-11-08·CVSS 6.0
CVE-2016-9385 [MEDIUM] CVE-2016-9385 xsa193 xen: x86 segment base write emulation lacking canonical address checks (XSA-193)
CVE-2016-9385 xsa193 xen: x86 segment base write emulation lacking canonical address checks (XSA-193)
ISSUE DESCRIPTION
Both writes to the FS and GS register base MSRs as well as the
WRFSBASE and WRGSBASE instructions require their input values to be
canonical, or a #GP fault will be raised. When the use of those
instructions by the hypervisor was enabled, the previous guard against
#GP faults (having recovery code attached) was accidentally removed.
IMPACT
A malicious guest administrator can crash the host, leading to a DoS.
VULNERABLE SYSTEMS
Xen versions 4.4 and onwards are affected. Xen versions 4.3 and
earlier are not affected.
The vulnerability is only exposed to x86 PV guests.
The vulnerability is NOT exposed to x86 HVM guests.
ARM systems are NOT vulnerable.
MITIGATION
R
http://www.securityfocus.com/bid/94472http://www.securitytracker.com/id/1037342http://xenbits.xen.org/xsa/advisory-193.htmlhttps://security.gentoo.org/glsa/201612-56https://support.citrix.com/article/CTX218775http://www.securityfocus.com/bid/94472http://www.securitytracker.com/id/1037342http://xenbits.xen.org/xsa/advisory-193.htmlhttps://security.gentoo.org/glsa/201612-56https://support.citrix.com/article/CTX218775
2017-01-23
Published