CVE-2016-6258

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

References

http://support.citrix.com/article/CTX214954

http://www.debian.org/security/2016/dsa-3633

http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html

http://www.securityfocus.com/bid/92131

http://www.securitytracker.com/id/1036446

http://xenbits.xen.org/xsa/advisory-182.html

http://xenbits.xen.org/xsa/xsa182-4.5.patch

http://xenbits.xen.org/xsa/xsa182-4.6.patch

http://xenbits.xen.org/xsa/xsa182-unstable.patch

https://security.gentoo.org/glsa/201611-09

Details

Source: MITRE

Published: 2016-08-02

Updated: 2017-07-01

Type: CWE-284

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Impact Score: 6

Exploitability Score: 2

Severity: HIGH

Tenable Plugins

View all (20 total)

IDNameProductFamilySeverity
140019OracleVM 3.4 : xen (OVMSA-2020-0039) (Bunker Buster) (Foreshadow) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (Meltdown) (POODLE) (Spectre)NessusOracleVM Local Security Checks
critical
111992OracleVM 3.4 : xen (OVMSA-2018-0248) (Bunker Buster) (Foreshadow) (Meltdown) (POODLE) (Spectre)NessusOracleVM Local Security Checks
critical
94893GLSA-201611-09 : Xen: Multiple vulnerabilities (Bunker Buster)NessusGentoo Local Security Checks
high
94608SUSE SLES11 Security Update : xen (SUSE-SU-2016:2725-1) (Bunker Buster)NessusSuSE Local Security Checks
critical
94269SUSE SLES12 Security Update : xen (SUSE-SU-2016:2533-1) (Bunker Buster)NessusSuSE Local Security Checks
critical
94267SUSE SLES11 Security Update : xen (SUSE-SU-2016:2528-1) (Bunker Buster)NessusSuSE Local Security Checks
critical
94038SUSE SLES11 Security Update : xen (SUSE-SU-2016:2507-1) (Bunker Buster)NessusSuSE Local Security Checks
high
94000openSUSE Security Update : xen (openSUSE-2016-1170) (Bunker Buster)NessusSuSE Local Security Checks
critical
93999openSUSE Security Update : xen (openSUSE-2016-1169) (Bunker Buster)NessusSuSE Local Security Checks
critical
93935SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2016:2473-1) (Bunker Buster)NessusSuSE Local Security Checks
high
93298SUSE SLES11 Security Update : xen (SUSE-SU-2016:2100-1) (Bunker Buster)NessusSuSE Local Security Checks
critical
93296SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2016:2093-1) (Bunker Buster)NessusSuSE Local Security Checks
critical
92796Fedora 23 : xen (2016-0049aa6e5d) (Bunker Buster)NessusFedora Local Security Checks
high
92766Fedora 24 : xen (2016-01cc766201) (Bunker Buster)NessusFedora Local Security Checks
high
92723Citrix XenServer Multiple Vulnerabilities (CTX214954) (Bunker Buster)NessusMisc.
high
92701Xen Privilege Escalation (XSA-182) (Bunker Buster)NessusMisc.
high
92674FreeBSD : xen-kernel -- x86: Privilege escalation in PV guests (032aa524-5854-11e6-b334-002590263bf5) (Bunker Buster)NessusFreeBSD Local Security Checks
high
92635Debian DLA-571-1 : xen security update (Bunker Buster)NessusDebian Local Security Checks
high
92614Debian DSA-3633-1 : xen - security update (Bunker Buster)NessusDebian Local Security Checks
high
92600OracleVM 3.4 : xen (OVMSA-2016-0088) (Bunker Buster)NessusOracleVM Local Security Checks
high