CVE-2016-2271: Medium severity xen xapi vulnerability
Published Feb 19, 2016
·Updated
VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.
Affected Software
2 affected components
XEN Xen=4.6.0
XEN Xen=4.6.1
Remediation
Patch Available
Event History
Feb 19, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2271?
CVE-2016-2271 is considered a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2016-2271?
To fix CVE-2016-2271, update to a patched version of Xen, specifically versions later than 4.6.1.
3
What systems are affected by CVE-2016-2271?
CVE-2016-2271 affects Xen versions 4.6.0 and 4.6.1 running on Intel or Cyrix CPU architectures.
4
What types of vulnerabilities does CVE-2016-2271 represent?
CVE-2016-2271 represents a denial of service vulnerability related to non-canonical RIP handling in HVM guest environments.
5
Can CVE-2016-2271 be exploited remotely?
CVE-2016-2271 requires local access to the HVM guest, thus it cannot be exploited remotely.