Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3663-1 | xen security update |
EUVD |
EUVD-2016-8022 | Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T01:50:47.467Z
Reserved: 2016-09-06T00:00:00
Link: CVE-2016-7154
No data.
Status : Deferred
Published: 2016-09-21T14:25:27.160
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-7154
OpenCVE Enrichment
No data.
Debian DSA
EUVD