CVE-2016-1570: Input Validation
The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier (MFN) to the (1) MMUEXTMARKSUPER or (2) MMUEXTUNMARKSUPER sub-op in the HYPERVISORmmuextop hypercall or (3) unknown vectors related to page table updates.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1570?
CVE-2016-1570 has been classified with a medium severity rating, potentially allowing local PV guests to gain unauthorized access to sensitive information.
How do I fix CVE-2016-1570?
To mitigate CVE-2016-1570, upgrade to a fixed version of Xen that addresses this vulnerability.
Which versions of Xen are affected by CVE-2016-1570?
CVE-2016-1570 affects Xen versions 3.4.0, 3.4.1, and 4.1.x through 4.6.x.
What types of vulnerabilities are associated with CVE-2016-1570?
CVE-2016-1570 can lead to information leakage, privilege escalation, and denial of service.
Who should be concerned about CVE-2016-1570?
Organizations using affected versions of Xen should be concerned about CVE-2016-1570 and immediately assess their systems for potential impact.