Xen Multiple Vulnerabilities (XSA-186, XSA-187)

This script is Copyright (C) 2016-2017 Tenable Network Security, Inc.


Synopsis :

The remote Xen hypervisor installation is missing a security update.

Description :

According to its self-reported version number, the Xen hypervisor
installed on the remote host is affected by multiple vulnerabilities :

- A flaw exists due to improper handling of instruction
pointer truncation when emulating HVM instructions. An
attacker on the guest can exploit this to gain elevated
privileges on the host. (CVE-2016-7093)

- An overflow condition exists due to x86 HVM guests running
with shadow paging using a subset of the x86 emulator to
handle the guest writing to pagetables. An attacker on the
guest can exploit this to cause a denial of service
condition on the host. (CVE-2016-7094)

Note that Nessus has checked the changeset versions based on the
xen.git change log. Nessus did not check guest hardware configurations
or if patches were applied manually to the source code before a
recompile and reinstall.

See also :

https://xenbits.xen.org/xsa/advisory-186.html
https://xenbits.xen.org/xsa/advisory-187.html
https://xenbits.xen.org/gitweb/?p=xen.git;a=summary

Solution :

Apply the appropriate patch according to the vendor advisory.

Risk factor :

High / CVSS Base Score : 7.2
(CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 5.3
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Misc.

Nessus Plugin ID: 93802 ()

Bugtraq ID: 92864
92865

CVE ID: CVE-2016-7093
CVE-2016-7094

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now