CVE-2016-3158

Publication date 13 April 2016

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

3.8 · Low

Score breakdown

The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.

Status

Package Ubuntu Release Status
xen 16.04 LTS xenial
Fixed 4.6.0-1ubuntu4.1
15.10 wily
Fixed 4.5.1-0ubuntu1.4
14.04 LTS trusty
Fixed 4.4.2-0ubuntu0.14.04.6
12.04 LTS precise
Fixed 4.1.6.1-0ubuntu0.12.04.11

Severity score breakdown

Parameter Value
Base score 3.8 · Low
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Changed
Confidentiality Low
Integrity impact None
Availability impact None
Vector CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N