Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-4480

Опубликовано: 18 мая 2016
Источник: nvd
CVSS3: 8.4
CVSS2: 7.2
EPSS Низкий

Описание

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:oracle:vm_server:3.2:*:*:*:*:*:*:*
cpe:2.3:o:oracle:vm_server:3.3:*:*:*:*:*:*:*
cpe:2.3:o:oracle:vm_server:3.4:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*
Версия до 4.6.1 (включая)

EPSS

Процентиль: 66%
0.00516
Низкий

8.4 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

CVSS3: 8.4
ubuntu
больше 9 лет назад

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

redhat
больше 9 лет назад

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

CVSS3: 8.4
debian
больше 9 лет назад

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6. ...

CVSS3: 8.4
github
больше 3 лет назад

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

suse-cvrf
больше 9 лет назад

Security update for xen

EPSS

Процентиль: 66%
0.00516
Низкий

8.4 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-264