CVE-2016-9385: Input Validation
Published Jan 23, 2017
·Updated
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.
Affected Software
20 affected components
XEN Xen=4.4.0
XEN Xen=4.4.1
XEN Xen=4.4.2
XEN Xen=4.4.3
XEN Xen=4.4.4
XEN Xen=4.5.0
XEN Xen=4.5.1
XEN Xen=4.5.2
XEN Xen=4.5.3
XEN Xen=4.5.5
XEN Xen=4.6.0
XEN Xen=4.6.1
XEN Xen=4.6.3
XEN Xen=4.6.4
XEN Xen=4.7.0
XEN Xen=4.7.1
Citrix XenServer=6.0.2
Citrix XenServer=6.2.0
Citrix XenServer=6.5
Citrix XenServer=7.0
Remediation
Patch Available
Patch Available
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9385?
CVE-2016-9385 is classified as a denial of service vulnerability that can lead to a host crash.
2
How do I fix CVE-2016-9385?
To fix CVE-2016-9385, you should upgrade to a version of Xen that is not affected, such as Xen 4.8.0 or later.
3
Which versions of Xen are affected by CVE-2016-9385?
CVE-2016-9385 affects Xen versions 4.4.x through 4.7.x.
4
How does CVE-2016-9385 affect virtual machines?
CVE-2016-9385 allows local x86 PV guest OS administrators to exploit the vulnerability to crash the host.
5
What type of systems are impacted by CVE-2016-9385?
CVE-2016-9385 impacts systems running vulnerable versions of the Xen hypervisor, including XenServer.