Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183275.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183350.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184209.html
http://support.citrix.com/article/CTX209443
http://www.debian.org/security/2016/dsa-3554
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/bid/86318
Source: MITRE
Published: 2016-04-19
Updated: 2016-12-03
Type: CWE-264
Base Score: 7.2
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
Impact Score: 10
Exploitability Score: 3.9
Severity: HIGH
Base Score: 8.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Impact Score: 6
Exploitability Score: 2
Severity: HIGH
OR
OR
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
OR
cpe:2.3:o:oracle:vm_server:3.2:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
94608 | SUSE SLES11 Security Update : xen (SUSE-SU-2016:2725-1) (Bunker Buster) | Nessus | SuSE Local Security Checks | high |
94269 | SUSE SLES12 Security Update : xen (SUSE-SU-2016:2533-1) (Bunker Buster) | Nessus | SuSE Local Security Checks | high |
94267 | SUSE SLES11 Security Update : xen (SUSE-SU-2016:2528-1) (Bunker Buster) | Nessus | SuSE Local Security Checks | high |
94000 | openSUSE Security Update : xen (openSUSE-2016-1170) (Bunker Buster) | Nessus | SuSE Local Security Checks | high |
93999 | openSUSE Security Update : xen (openSUSE-2016-1169) (Bunker Buster) | Nessus | SuSE Local Security Checks | high |
93298 | SUSE SLES11 Security Update : xen (SUSE-SU-2016:2100-1) (Bunker Buster) | Nessus | SuSE Local Security Checks | high |
93296 | SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2016:2093-1) (Bunker Buster) | Nessus | SuSE Local Security Checks | high |
92635 | Debian DLA-571-1 : xen security update (Bunker Buster) | Nessus | Debian Local Security Checks | high |
92602 | OracleVM 3.2 : xen (OVMSA-2016-0090) | Nessus | OracleVM Local Security Checks | high |
92601 | OracleVM 3.3 : xen (OVMSA-2016-0089) | Nessus | OracleVM Local Security Checks | high |
92600 | OracleVM 3.4 : xen (OVMSA-2016-0088) (Bunker Buster) | Nessus | OracleVM Local Security Checks | high |
91934 | FreeBSD : xen-kernel -- x86 shadow pagetables: address width overflow (d51ced72-4212-11e6-942d-bc5ff45d0f28) | Nessus | FreeBSD Local Security Checks | high |
91756 | OracleVM 3.2 : xen (OVMSA-2016-0081) | Nessus | OracleVM Local Security Checks | high |
90954 | Fedora 24 : xen-4.6.1-6.fc24 (2016-48e72b7bc5) | Nessus | Fedora Local Security Checks | high |
90814 | Fedora 22 : xen-4.5.3-2.fc22 (2016-75063477ca) | Nessus | Fedora Local Security Checks | high |
90811 | Fedora 23 : xen-4.5.3-2.fc23 (2016-35d7b09908) | Nessus | Fedora Local Security Checks | high |
90638 | Debian DSA-3554-1 : xen - security update | Nessus | Debian Local Security Checks | high |