{"api_version":"1","generated_at":"2026-07-23T20:31:06+00:00","cve":"CVE-2016-3158","urls":{"html":"https://cve.report/CVE-2016-3158","api":"https://cve.report/api/cve/CVE-2016-3158.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-3158","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-3158"},"summary":{"title":"CVE-2016-3158","description":"The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.","state":"PUBLISHED","assigner":"mitre","published_at":"2016-04-13 16:59:18","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","CWE-284","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"3.8","severity":"LOW","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.7","severity":"","vector":"AV:L/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html","name":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Oracle VM Server for x86 Bulletin - July 2016","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181729.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181729.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 23 Update: xen-4.5.3-1.fc23","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1035435","name":"http://www.securitytracker.com/id/1035435","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Xen Lets Local Users on a Guest System Obtain Register Contents from the Target Guest System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181699.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181699.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 22 Update: xen-4.5.3-1.fc22","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://xenbits.xen.org/xsa/xsa172.patch","name":"http://xenbits.xen.org/xsa/xsa172.patch","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2016/dsa-3554","name":"http://www.debian.org/security/2016/dsa-3554","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3554-1 xen","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://xenbits.xen.org/xsa/advisory-172.html","name":"http://xenbits.xen.org/xsa/advisory-172.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"XSA-172 - Xen Security Advisories","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://xenbits.xen.org/xsa/xsa172-4.3.patch","name":"http://xenbits.xen.org/xsa/xsa172-4.3.patch","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://support.citrix.com/article/CTX209443","name":"http://support.citrix.com/article/CTX209443","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Citrix XenServer Multiple Security Updates","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/85714","name":"http://www.securityfocus.com/bid/85714","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Xen CVE-2016-3158 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-3158","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-3158","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"3158","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"22","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"3158","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"23","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"3158","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"oracle","cpe5":"vm_server","cpe6":"3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"3158","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"oracle","cpe5":"vm_server","cpe6":"3.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"3158","vulnerable":"1","versionEndIncluding":"4.4.0","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"xen","cpe5":"xen","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T23:47:57.667Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html"},{"name":"FEDORA-2016-5f196e4e4a","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181699.html"},{"name":"85714","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/85714"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://xenbits.xen.org/xsa/xsa172-4.3.patch"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://xenbits.xen.org/xsa/advisory-172.html"},{"name":"FEDORA-2016-e5432ca977","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181729.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://xenbits.xen.org/xsa/xsa172.patch"},{"name":"1035435","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1035435"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.citrix.com/article/CTX209443"},{"name":"DSA-3554","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2016/dsa-3554"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-03-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-11-30T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html"},{"name":"FEDORA-2016-5f196e4e4a","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181699.html"},{"name":"85714","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/85714"},{"tags":["x_refsource_CONFIRM"],"url":"http://xenbits.xen.org/xsa/xsa172-4.3.patch"},{"tags":["x_refsource_CONFIRM"],"url":"http://xenbits.xen.org/xsa/advisory-172.html"},{"name":"FEDORA-2016-e5432ca977","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181729.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://xenbits.xen.org/xsa/xsa172.patch"},{"name":"1035435","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1035435"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.citrix.com/article/CTX209443"},{"name":"DSA-3554","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2016/dsa-3554"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2016-3158","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html"},{"name":"FEDORA-2016-5f196e4e4a","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181699.html"},{"name":"85714","refsource":"BID","url":"http://www.securityfocus.com/bid/85714"},{"name":"http://xenbits.xen.org/xsa/xsa172-4.3.patch","refsource":"CONFIRM","url":"http://xenbits.xen.org/xsa/xsa172-4.3.patch"},{"name":"http://xenbits.xen.org/xsa/advisory-172.html","refsource":"CONFIRM","url":"http://xenbits.xen.org/xsa/advisory-172.html"},{"name":"FEDORA-2016-e5432ca977","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-April/181729.html"},{"name":"http://xenbits.xen.org/xsa/xsa172.patch","refsource":"CONFIRM","url":"http://xenbits.xen.org/xsa/xsa172.patch"},{"name":"1035435","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1035435"},{"name":"http://support.citrix.com/article/CTX209443","refsource":"CONFIRM","url":"http://support.citrix.com/article/CTX209443"},{"name":"DSA-3554","refsource":"DEBIAN","url":"http://www.debian.org/security/2016/dsa-3554"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2016-3158","datePublished":"2016-04-13T16:00:00.000Z","dateReserved":"2016-03-15T00:00:00.000Z","dateUpdated":"2024-08-05T23:47:57.667Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-04-13 16:59:18","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","CWE-284","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.1,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*","versionEndIncluding":"4.4.0","matchCriteriaId":"0C014033-2C0A-4484-9390-1C68583957DD"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*","matchCriteriaId":"253C303A-E577-4488-93E6-68A8DD942C38"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*","matchCriteriaId":"E79AB8DD-C907-4038-A931-1A5A4CFB6A5B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:oracle:vm_server:3.3:*:*:*:*:*:*:*","matchCriteriaId":"C2D62B2C-40E5-41B7-9DAA-029BCD079054"},{"vulnerable":true,"criteria":"cpe:2.3:o:oracle:vm_server:3.4:*:*:*:*:*:*:*","matchCriteriaId":"4BA58099-26F7-4B01-B9FC-275F012FE9C6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"3158","Ordinal":"1","Title":"CVE-2016-3158","CVE":"CVE-2016-3158","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"3158","Ordinal":"1","NoteData":"The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.","Type":"Description","Title":"CVE-2016-3158"},{"CveYear":"2016","CveId":"3158","Ordinal":"2","NoteData":"2016-04-13","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"3158","Ordinal":"3","NoteData":"2016-11-30","Type":"Other","Title":"Modified"}]}}}