VDB

ALPINE-CVE-2016-7093

ALPINE-CVE-2016-7093 PUBLISHED CVSS 8.199999809265137 HIGH

Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.

Risk Scores

CVSS 3.0
8.199999809265137
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.22xen0, 0, 4.0.1-r0
Alpine:v3.15xen0, 4.5.0-r0, 0
Alpine:v3.20xen4.1.0-r2, 4.0.1-r0, 4.0.1-r1
Alpine:v3.12xen4.3.0-r6, 4.0.1-r3, 4.1.0-r0
Alpine:v3.7xen4.6.3-r1, 0, 4.0.1-r1
Alpine:v3.19xen4.0.1-r1, 4.0.1-r2, 4.0.1-r3
Alpine:v3.8xen0, 4.2.1-r1, 4.0.1-r0
Alpine:v3.5xen0, 4.7.0-r0, 4.6.3-r1
Alpine:v3.9xen4.3.1-r1, 4.7.0-r0, 4.6.3-r1
Alpine:v3.18xen4.2.2-r11, 4.0.1-r0, 4.0.1-r1
Alpine:v3.14xen0, 4.0.1-r1, 4.0.1-r2
Alpine:v3.24xen0
Alpine:v3.17xen0, 4.7.0-r0, 4.6.3-r1
Alpine:v3.4xen4.0.1-r0, 4.0.1-r2, 4.0.1-r3
Alpine:v3.6xen4.6.0-r5, 0, 4.0.1-r0
Alpine:v3.23xen4.7.0-r0, 4.0.1-r0, 4.0.1-r2
Alpine:v3.11xen4.6.0-r1, 4.7.0-r0, 4.0.1-r0
Alpine:v3.13xen4.2.2-r11, 0, 4.7.0-r0
Alpine:v3.21xen4.1.2-r8, 4.6.0-r0, 4.6.0-r1
Alpine:v3.16xen0, 4.0.1-r2, 4.7.0-r0

…and 1 more

Timeline

  • Sep 21, 2016 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jun 9, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›