CVE-2016-9377: Medium severity XEN Xen vulnerability
Published Feb 22, 2017
·Updated
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
Affected Software
11 affected components
XEN Xen=4.5.0
XEN Xen=4.5.1
XEN Xen=4.5.2
XEN Xen=4.5.3
XEN Xen=4.5.5
XEN Xen=4.6.0
XEN Xen=4.6.1
XEN Xen=4.6.3
XEN Xen=4.6.4
XEN Xen=4.7.0
XEN Xen=4.7.1
Remediation
Patch Available
Event History
Feb 22, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9377?
CVE-2016-9377 is classified as a denial of service vulnerability, leading to potential guest OS crashes.
2
How do I fix CVE-2016-9377?
To mitigate CVE-2016-9377, upgrade to a Xen version that addresses this vulnerability, specifically 4.5.4 or later.
3
Which versions of Xen are affected by CVE-2016-9377?
CVE-2016-9377 affects Xen versions 4.5.0 through 4.7.1 on AMD systems without the NRip feature.
4
What type of systems is CVE-2016-9377 applicable to?
CVE-2016-9377 is applicable to AMD systems running specified versions of Xen hypervisor.
5
Can CVE-2016-9377 be exploited remotely?
CVE-2016-9377 requires local access to the HVM guest OS, making it a local exploitation risk.