First published: Fri Oct 07 2016(Updated: )
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | <=4.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7777 is considered a high severity vulnerability due to its potential for local users to manipulate critical register states.
To fix CVE-2016-7777, upgrade to Xen version 4.8.0 or later where the vulnerability has been addressed.
Any local x86 HVM guest OS user on Xen versions 4.7.x and earlier is affected by CVE-2016-7777.
CVE-2016-7777 allows local users to read or modify FPU, MMX, or XMM register state information of arbitrary tasks.
No, CVE-2016-7777 is a local exploit, meaning an attacker needs access to the guest OS to exploit this vulnerability.