CVE-2016-4440: High severity linux kernel vulnerability

Published May 20, 2016
·
Updated

arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access on the host OS, and consequently cause a denial of service (host OS crash) or possibly execute arbitrary code on the host OS, via x2APIC mode.

Other sources

Linux kernel built with the Kernel-based virtual machine(CONFIGKVM) along with Hyper-v Synthetic Interrupt Controller(SynIC) support is vulnerable to an undue APIC register access issue. In that a guest with SynIC enabled, could gain access to host's Machine Specific Registers(MSR).

A privileged user inside guest could use this flaw to crash the host kernel resulting in DoS OR potentially leverage it to escalate privileges on the host.

Upstream patch: --------------- -> http://permalink.gmane.org/gmane.comp.emulators.kvm.devel/152191

Reference: ---------- -> http://comments.gmane.org/gmane.comp.emulators.kvm.devel/152100

Note: It requires fairly latest features to be available and enabled on the host(APICv) as well as in the guest(-hv-synic).

— Red Hat

Affected Software

1 affected component
Linux Linux kernel>=4.5<4.7

Event History

May 20, 2016
Data Sourced
06:37 AM
DescriptionSeverityAffected Software
Jun 27, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2016-4440?

CVE-2016-4440 is classified as a high severity vulnerability due to its potential to allow denial of service or arbitrary code execution on the host OS.

2

How do I fix CVE-2016-4440?

To fix CVE-2016-4440, update your Linux kernel to version 4.7 or later.

3

What causes CVE-2016-4440?

CVE-2016-4440 is caused by mishandling of the APICv on/off state in the Linux kernel, allowing guest OS users unauthorized access to APIC MSRs.

4

Who is affected by CVE-2016-4440?

CVE-2016-4440 affects users running vulnerable versions of the Linux kernel from version 4.5 up to 4.6.3.

5

What are the potential impacts of CVE-2016-4440?

The potential impacts of CVE-2016-4440 include host OS crashes and the risk of arbitrary code execution by a guest OS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203