CVE-2016-9818: Medium severity XEN Xen vulnerability
Published Feb 27, 2017
·Updated
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at HYP.
Affected Software
2 affected components
XEN Xen=4.7.0
XEN Xen=4.7.1
Remediation
Patch Available
Patch Available
Event History
Feb 27, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9818?
CVE-2016-9818 has a high severity due to its potential to cause a denial of service resulting in a host crash.
2
How do I fix CVE-2016-9818?
To fix CVE-2016-9818, upgrade Xen to version 4.7.2 or later, as it contains patches addressing this vulnerability.
3
Who is affected by CVE-2016-9818?
Local ARM guest OS users running Xen versions 4.7.0 and 4.7.1 are affected by CVE-2016-9818.
4
What kind of attack does CVE-2016-9818 facilitate?
CVE-2016-9818 facilitates denial of service attacks via asynchronous aborts while in HYP state.
5
Is there a mitigation for CVE-2016-9818?
There are no known mitigations other than upgrading to a secure version, as the flaw cannot be worked around.