CVE-2016-6259

Publication date 2 August 2016

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

6.2 · Medium

Score breakdown

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.

Read the notes from the security team

Status

Package Ubuntu Release Status
xen 16.04 LTS xenial
Fixed 4.6.0-1ubuntu4.2
15.10 wily Ignored end of life
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected

Notes


mdeslaur

4.5+ only

Severity score breakdown

Parameter Value
Base score 6.2 · Medium
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H