CVE-2016-3961

MEDIUM

Xen & Linux Kernel <4.5.x - DoS

Title source: llm

Description

Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 31.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-20
Status draft

Affected Products (4)

canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
xen/xen < 4.5.3

Timeline

Published Apr 15, 2016
Tracked Since Feb 18, 2026