← Back

CVE-2016-6258

nvd nist
Published: Aug 2, 2016Modified: May 6, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD

Description

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

Affected (33)

Products: Xen: Xen · Citrix: Xenserver
1 product
Xen
1 product
Xenserver
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Xen
Version 3.4.0
Version 3.4.2
Version 3.4.3
Version 3.4.4
Version 4.0.0
Version 4.0.1
Version 4.0.3
Version 4.0.4
Version 4.1.0
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.1.4
Version 4.1.5
Version 4.2.0
Version 4.2.1
Version 4.2.2
Version 4.2.3
Version 4.3.0
Version 4.3.1
Version 4.4.0
Version 4.4.1
Version 4.5.0
Version 4.6.0
Version 4.6.1
Version 4.6.3
Version 4.7.0
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Citrix
Version 6.0.2
Version 6.0
Version 6.1
Version 6.2.0 sp1
Version 6.5.0 sp1
Version 7.0

References (20)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.