← Back

CVE-2016-3159

nvd nist
Published: Apr 13, 2016Modified: May 6, 2026

JSON object

Loading...
3.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Exploitability: 2.0 / Impact: 1.4
Source: NVD

Description

The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.

Affected (9)

Products: Oracle: Vm Server · Xen: Xen · Fedoraproject: Fedora · +1 more
Show all products
1 product
Vm Server
1 product
Xen
1 product
Fedora
1 product
Debian Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 3.3
Version 3.4
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Xen
From 4.3.0 to 4.3.4
From 4.4.0 to 4.4.4
From 4.5.0 to 4.5.3
From 4.6.0 to 4.6.1
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 22
Version 23
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0

References (18)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.