CVE-2016-1571
N/A
N/A
Summary
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID instruction, which triggers a hypervisor bug check.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.debian.org/security/2016/dsa-3519
- http://www.securitytracker.com/id/1034745
- http://support.citrix.com/article/CTX205496
- http://xenbits.xen.org/xsa/advisory-168.html
References
- http://www.debian.org/security/2016/dsa-3519
- http://www.securitytracker.com/id/1034745
- http://support.citrix.com/article/CTX205496
- http://xenbits.xen.org/xsa/advisory-168.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.