CVE-2016-7154

MEDIUM

Xen - Use After Free

Title source: rule

Description

Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number.

Scores

CVSS v3 6.7
EPSS 0.0009
EPSS Percentile 26.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-416
Status published

Affected Products (6)

n/a/n/a
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen

Timeline

Published Sep 21, 2016
Tracked Since Feb 18, 2026