CVE-2016-4963: Medium severity xen xapi vulnerability
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4963?
The severity of CVE-2016-4963 is considered moderate, as it allows denial of service specifically affecting management tool operation in vulnerable Xen versions.
How does CVE-2016-4963 affect my Xen environment?
CVE-2016-4963 allows local guest OS users to manipulate xenstore backend directories, potentially causing confusion in management tools and leading to a denial of service.
Which versions of Xen are affected by CVE-2016-4963?
CVE-2016-4963 affects Xen versions from 4.0.0 to 4.6.1, including all versions in between.
How do I fix CVE-2016-4963?
To fix CVE-2016-4963, update your Xen installation to a version beyond 4.6.1 where the vulnerability has been addressed.
What mitigations exist for CVE-2016-4963?
There are no specific mitigations other than upgrading to an unaffected version of Xen to resolve CVE-2016-4963.