CVE-2016-9817: Medium severity XEN Xen vulnerability
Published Feb 27, 2017
·Updated
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESREL2.EA bit set.
Affected Software
2 affected components
XEN Xen=4.7.0
XEN Xen=4.7.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Feb 27, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9817?
CVE-2016-9817 has a medium severity level due to its potential to cause denial of service on the host system.
2
How do I fix CVE-2016-9817?
To fix CVE-2016-9817, you should upgrade to Xen version 4.7.2 or later, which includes patches addressing this vulnerability.
3
Who is affected by CVE-2016-9817?
CVE-2016-9817 affects local ARM guest OS users running Xen versions 4.7.0 and 4.7.1.
4
What sort of attacks can exploit CVE-2016-9817?
CVE-2016-9817 can be exploited through data or prefetch aborts that lead to host crashes.
5
Can CVE-2016-9817 lead to remote exploitation?
No, CVE-2016-9817 is a local vulnerability and requires local access to the ARM guest OS to exploit.