CVE-2016-7777
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the…
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.
- CVSS 3.0
- 6.3 MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- xen/xen
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/93344Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036942Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-190.htmlMitigation, Patch, Vendor Advisory
- https://security.gentoo.org/glsa/201611-09
- https://support.citrix.com/article/CTX217363
- http://www.securityfocus.com/bid/93344Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036942Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-190.htmlMitigation, Patch, Vendor Advisory
- https://security.gentoo.org/glsa/201611-09
- https://support.citrix.com/article/CTX217363
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.