Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6258

Опубликовано: 26 июл. 2016
Источник: redhat
CVSS3: 8.5
CVSS2: 6
EPSS Низкий

Описание

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

A vulnerability was found Xen's MMU emulation for x86 PV guests. A malicious administrator of an x86 PV guest could control some of the page table bits, allowing potential control of memory and code execution in the host. x86 HVM and ARM guests could not exploit this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xenWill not fix

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1355987xen: x86: Privilege escalation in PV guests (XSA-182)

EPSS

Процентиль: 30%
0.00112
Низкий

8.5 High

CVSS3

6 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 9 лет назад

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

CVSS3: 8.8
nvd
больше 9 лет назад

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

CVSS3: 8.8
debian
больше 9 лет назад

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows ...

CVSS3: 8.8
github
больше 3 лет назад

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

suse-cvrf
больше 9 лет назад

Security update for xen

EPSS

Процентиль: 30%
0.00112
Низкий

8.5 High

CVSS3

6 Medium

CVSS2