Alpine: xen: security update to 4.16.5-r5

low Tenable Self-Hosted Container Security Plugin ID 408172

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Arm provides multiple helpers to clean & invalidate the cache for a given region. This is, for instance,
used when allocating guest memory to ensure any writes (such as the ones during scrubbing) have reached
memory before handing over the page to a guest. Unfortunately, the arithmetics in the helpers can overflow
and would then result to skip the cache cleaning/invalidation. Therefore there is no guarantee when all
the writes will reach the memory. This undefined behavior was meant to be addressed by XSA-437, but the
approach was not sufficient. (CVE-2023-46837)

See Also

https://security.alpinelinux.org/vuln/CVE-2023-46837

Plugin Details

Severity: Low

ID: 408172

Version: Revision 1.25

Type: Local

Published: 12/13/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Low

Base Score: 1.7

Temporal Score: 1.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2023-46837

CVSS v3

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.9

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 11/30/2023

Reference Information

CVE: CVE-2023-46837

IAVB: 2023-B-0090-S