CVE-2016-9932
published 2017-01-26CVE-2016-9932: CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a…
PriorityP49low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.42%
34.2th percentile
CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.8.0~rc3-1 (bookworm) | xen 4.8.0~rc3-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Xen 4.4.x/4.5.x/4.6.x/4.7.x CMPXCHG16B Emulation information disclosure (XSA-200 / Nessus ID 95787)
vuldb·2026-05-14·CVSS 3.3
CVE-2016-9932 [LOW] Xen 4.4.x/4.5.x/4.6.x/4.7.x CMPXCHG16B Emulation information disclosure (XSA-200 / Nessus ID 95787)
A vulnerability, which was classified as problematic, was found in Xen 4.4.x/4.5.x/4.6.x/4.7.x. Affected by this issue is some unknown functionality of the component CMPXCHG16B Emulation. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2016-9932. Local access is required to approach this attack. No exploit exists.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-888m-xr85-xxqp: CMPXCHG8B emulation in Xen 3
ghsa_unreviewed·2022-05-17
CVE-2016-9932 [LOW] CWE-200 GHSA-888m-xr85-xxqp: CMPXCHG8B emulation in Xen 3
CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
OSV
CVE-2016-9932: CMPXCHG8B emulation in Xen 3
osv·2017-01-26·CVSS 3.3
CVE-2016-9932 [LOW] CVE-2016-9932: CMPXCHG8B emulation in Xen 3
CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
Red Hat
xen: x86 CMPXCHG8B emulation fails to ignore operand size override (XSA-200)
vendor_redhat·2016-12-13·CVSS 3.3
CVE-2016-9932 [LOW] xen: x86 CMPXCHG8B emulation fails to ignore operand size override (XSA-200)
xen: x86 CMPXCHG8B emulation fails to ignore operand size override (XSA-200)
CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
Package: xen (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2016-9932: xen - CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM g...
vendor_debian·2016·CVSS 3.3
CVE-2016-9932 [LOW] CVE-2016-9932: xen - CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM g...
CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
Scope: local
bookworm: resolved (fixed in 4.8.0~rc3-1)
bullseye: resolved (fixed in 4.8.0~rc3-1)
forky: resolved (fixed in 4.8.0~rc3-1)
sid: resolved (fixed in 4.8.0~rc3-1)
trixie: resolved (fixed in 4.8.0~rc3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9932 xsa200 xen: x86 CMPXCHG8B emulation fails to ignore operand size override (XSA-200) [fedora-all]
bugzilla·2016-12-13·CVSS 3.3
CVE-2016-9932 [LOW] CVE-2016-9932 xsa200 xen: x86 CMPXCHG8B emulation fails to ignore operand size override (XSA-200) [fedora-all]
CVE-2016-9932 xsa200 xen: x86 CMPXCHG8B emulation fails to ignore operand size override (XSA-200) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2016-9932 xsa200 xen: x86 CMPXCHG8B emulation fails to ignore operand size override (XSA-200)
bugzilla·2016-11-29·CVSS 3.3
CVE-2016-9932 [LOW] CVE-2016-9932 xsa200 xen: x86 CMPXCHG8B emulation fails to ignore operand size override (XSA-200)
CVE-2016-9932 xsa200 xen: x86 CMPXCHG8B emulation fails to ignore operand size override (XSA-200)
ISSUE DESCRIPTION
The x86 instruction CMPXCHG8B is supposed to ignore legacy operand
size overrides; it only honors the REX.W override (making it
CMPXCHG16B). So, the operand size is always 8 or 16.
When support for CMPXCHG16B emulation was added to the instruction
emulator, this restriction on the set of possible operand sizes was
relied on in some parts of the emulation; but a wrong, fully general,
operand size value was used for other parts of the emulation.
As a result, if a guest uses a supposedly-ignored operand size prefix,
a small amount of hypervisor stack data is leaked to the guests: a 96
bit leak to guests running in 64-bit mode; or, a 32 bit leak to other
guests.
IMPACT
A ma
http://www.debian.org/security/2017/dsa-3847http://www.securityfocus.com/bid/94863http://www.securitytracker.com/id/1037468http://xenbits.xen.org/xsa/advisory-200.htmlhttps://security.gentoo.org/glsa/201612-56https://support.citrix.com/article/CTX219378http://www.debian.org/security/2017/dsa-3847http://www.securityfocus.com/bid/94863http://www.securitytracker.com/id/1037468http://xenbits.xen.org/xsa/advisory-200.htmlhttps://security.gentoo.org/glsa/201612-56https://support.citrix.com/article/CTX219378
2017-01-26
Published