CVE-2016-7093
High
CVE-2016-7093
Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.
Exploit probability
0.4%
Published
September 21, 2016
Required by
Not available
Last source change
April 16, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2016-7093
View original source
Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.
05 / REFERENCES
Further evidence
- http://support.citrix.com/article/CTX216071
- http://www.securityfocus.com/bid/92865
- http://www.securitytracker.com/id/1036752
- http://xenbits.xen.org/xsa/advisory-186.html
- http://xenbits.xen.org/xsa/xsa186-0001-x86-emulate-Correct-boundary-interactions-of-emulate.patch
- https://security.gentoo.org/glsa/201611-09