← Back

CVE-2016-4480

nvd nist
Published: May 18, 2016Modified: May 6, 2026

JSON object

Loading...
8.4
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.5 / Impact: 5.9
Source: NVD

Description

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

Affected (4)

Products: Oracle: Vm Server · Xen: Xen
1 product
Vm Server
1 product
Xen
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 3.2
Version 3.3
Version 3.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.6.1

Related CWEs

References (10)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.