8.5
CVSSv3

CVE-2016-1570

Published: 22/01/2016 Updated: 30/10/2018
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 8.5 | Impact Score: 6 | Exploitability Score: 1.8
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x up to and including 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier (MFN) to the (1) MMUEXT_MARK_SUPER or (2) MMUEXT_UNMARK_SUPER sub-op in the HYPERVISOR_mmuext_op hypercall or (3) unknown vectors related to page table updates.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen 4.5.1

xen xen 4.5.0

xen xen 4.3.3

xen xen 4.3.2

xen xen 4.3.1

xen xen 4.2.0

xen xen 4.1.6.1

xen xen 4.1.0

xen xen 3.4.1

xen xen 4.6.0

xen xen 4.5.2

xen xen 4.3.4

xen xen 4.2.2

xen xen 4.2.1

xen xen 4.1.2

xen xen 4.1.1

xen xen 4.4.3

xen xen 4.4.2

xen xen 4.3.0

xen xen 4.2.5

xen xen 4.1.6

xen xen 4.1.5

xen xen 3.4.0

xen xen 4.4.0

xen xen 4.4.1

xen xen 4.2.4

xen xen 4.2.3

xen xen 4.1.4

xen xen 4.1.3

Vendor Advisories

Debian Bug report logs - #823620 Multiple security issues Package: src:xen; Maintainer for src:xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 6 May 2016 18:03:02 UTC Severity: grave Tags: security Fixed in versions xen/480~rc3-1, xen/48 ...
Multiple security issues have been found in the Xen virtualisation solution, which may result in denial of service or information disclosure The oldstable distribution (wheezy) will be updated in a separate DSA For the stable distribution (jessie), these problems have been fixed in version 441-9+deb8u4 For the unstable distribution (sid), thes ...
The PV superpage functionality in arch/x86/mmc in Xen 340, 341, and 41x through 46x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier (MFN) to the (1) MMUEXT_MARK_SUPER or (2) MMUEXT_UNMARK_SUPER sub-op in the HYPERVISOR_mmuext_ ...