ZeroHour

CVE-2016-4480

CVSS 3.0
8.4 high
EPSS
<1%p44
Published
()
Modified
Description

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

Vendors
oraclexen
Products
vm server, xen
Weakness
CWE-264
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.