First published: Mon Feb 27 2017(Updated: )
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESR_EL2.EA bit set.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | =4.7.0 | |
Xen xen-unstable | =4.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9817 has a medium severity level due to its potential to cause denial of service on the host system.
To fix CVE-2016-9817, you should upgrade to Xen version 4.7.2 or later, which includes patches addressing this vulnerability.
CVE-2016-9817 affects local ARM guest OS users running Xen versions 4.7.0 and 4.7.1.
CVE-2016-9817 can be exploited through data or prefetch aborts that lead to host crashes.
No, CVE-2016-9817 is a local vulnerability and requires local access to the ARM guest OS to exploit.