OracleVM 3.4 : xen (OVMSA-2016-0102)

High Nessus Plugin ID 93395


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :


- evtchn-fifo: prevent use after free (Boris Ostrovsky) (CVE-2016-7154)

- x86/segment: Bounds check accesses to emulation ctxt->seg_reg[] (Andrew Cooper) (CVE-2016-7094)

- x86/shadow: Avoid overflowing sh_ctxt->seg_reg[] (Andrew Cooper) (CVE-2016-7094)

- x86/32on64: don't allow recursive page tables from L3 (Jan Beulich) (CVE-2016-7092)


Update the affected xen / xen-tools packages.

See Also

Plugin Details

Severity: High

ID: 93395

File Name: oraclevm_OVMSA-2016-0102.nasl

Version: $Revision: 2.12 $

Type: local

Published: 2016/09/09

Modified: 2017/02/17

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C


Base Score: 8.2

Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:xen, p-cpe:/a:oracle:vm:xen-tools, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2016/09/08

Reference Information

CVE: CVE-2016-7092, CVE-2016-7094, CVE-2016-7154

OSVDB: 143907, 143908, 143909

IAVB: 2016-B-0140