Alpine: multiple xen packages: security update to 4.7.2-r0

critical Tenable Self-Hosted Container Security Plugin ID 424713

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support
before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation
is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU
process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
(CVE-2016-9603)

- An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x,
and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the
caller to drive hypervisor memory accesses outside of the guest provided input/output arrays.
(CVE-2017-7228)

See Also

https://security.alpinelinux.org/vuln/CVE-2016-9603

https://security.alpinelinux.org/vuln/CVE-2017-7228

Plugin Details

Severity: Critical

ID: 424713

Version: Revision 1.7

Type: Local

Published: 4/4/2025

Updated: 5/31/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: High

Score: 7.3

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2016-9603

CVSS v3

Risk Factor: Critical

Base Score: 9.9

Temporal Score: 8.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 3/14/2017

Reference Information

CVE: CVE-2016-9603, CVE-2017-7228

BID: 96893, 97375

IAVA: 2017-A-0072-S, 2017-A-0095-S

IAVB: 2017-B-0035-S, 2017-B-0042-S