CVE-2016-3158
Summary
| CVE | CVE-2016-3158 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-04-13 16:59:18 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076. |
Risk And Classification
Primary CVSS: v3.0 3.8 LOW from [email protected]
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Problem Types: CWE-200 | CWE-284 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 3.8 | LOW | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
| 2.0 | [email protected] | Primary | 1.7 | AV:L/AC:L/Au:S/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 22 | All | All | All |
| Operating System | Fedoraproject | Fedora | 23 | All | All | All |
| Operating System | Oracle | Vm Server | 3.3 | All | All | All |
| Operating System | Oracle | Vm Server | 3.4 | All | All | All |
| Operating System | Xen | Xen | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle VM Server for x86 Bulletin - July 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Vendor Advisory |
| [SECURITY] Fedora 23 Update: xen-4.5.3-1.fc23 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| Xen Lets Local Users on a Guest System Obtain Register Contents from the Target Guest System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 22 Update: xen-4.5.3-1.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| xenbits.xen.org/xsa/xsa172.patch | af854a3a-2127-422b-91ae-364da2661108 | xenbits.xen.org | Patch |
| Debian -- Security Information -- DSA-3554-1 xen | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| XSA-172 - Xen Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | xenbits.xen.org | Vendor Advisory |
| xenbits.xen.org/xsa/xsa172-4.3.patch | af854a3a-2127-422b-91ae-364da2661108 | xenbits.xen.org | Patch |
| Citrix XenServer Multiple Security Updates | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | |
| Xen CVE-2016-3158 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.