Candidate: CVE-2016-7154 PublicDate: 2016-09-21 14:25:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7154 http://xenbits.xen.org/xsa/advisory-188.html Description: Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number. Ubuntu-Description: Notes: tyhicks> only Xen 4.4.x is affected Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H [6.7 MEDIUM] Patches_xen: Tags_xen: universe-binary upstream_xen: needs-triage precise_xen: not-affected (4.1.6.1-0ubuntu0.12.04.11) trusty_xen: released (4.4.2-0ubuntu0.14.04.7) trusty/esm_xen: DNE (trusty was released [4.4.2-0ubuntu0.14.04.7]) vivid/ubuntu-core_xen: DNE vivid/stable-phone-overlay_xen: DNE xenial_xen: not-affected (4.6.0-1ubuntu4.1) esm-infra/xenial_xen: not-affected (4.6.0-1ubuntu4.1) devel_xen: not-affected