ALPINE-CVE-2016-7093 PUBLISHED CVSS 8.199999809265137 HIGH

Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.

Risk Scores

CVSS v3.0
8.199999809265137
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.22xen4.7.0-r0, 0, 4.0.1-r0
Alpine:v3.15xen0, 4.0.1-r0, 4.0.1-r1
Alpine:v3.20xen4.0.1-r0, 4.7.0-r0, 4.6.3-r1
Alpine:v3.12xen4.7.0-r0, 0, 4.0.1-r0
Alpine:v3.7xen4.2.2-r7, 4.7.0-r0, 4.6.3-r1
Alpine:v3.19xen0, 4.0.1-r0, 4.0.1-r1
Alpine:v3.8xen4.5.1-r2, 0, 4.0.1-r0
Alpine:v3.5xen4.6.3-r0, 4.6.1-r2, 4.6.1-r1
Alpine:v3.9xen4.5.1-r2, 0, 4.0.1-r0
Alpine:v3.18xen4.7.0-r0, 4.0.1-r0, 4.0.1-r1
Alpine:v3.14xen0, 4.0.1-r0, 4.0.1-r1
Alpine:v3.17xen0, 4.7.0-r0, 4.6.3-r1
Alpine:v3.4xen4.6.3-r1, 0, 4.0.1-r0
Alpine:v3.6xen4.6.0-r2, 4.6.1-r1, 4.6.1-r2
Alpine:v3.23xen4.6.0-r3, 0, 4.0.1-r0
Alpine:v3.11xen4.7.0-r0, 4.6.3-r1, 4.6.3-r0
Alpine:v3.13xen4.7.0-r0, 0, 4.0.1-r0
Alpine:v3.21xen4.7.0-r0, 4.6.3-r1, 4.6.3-r0
Alpine:v3.16xen0, 4.7.0-r0, 4.6.3-r1
Alpine:v3.10xen0, 4.7.0-r0, 4.6.3-r1

Timeline

References

Open in Interactive Console →