CVE-2016-7154
MEDIUMXen - Use After Free
Title source: ruleDescription
Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number.
References (8)
Scores
CVSS v3
6.7
EPSS
0.0009
EPSS Percentile
26.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-416
Status
published
Affected Products (6)
n/a/n/a
xen/xen
xen/xen
xen/xen
xen/xen
xen/xen
Timeline
Published
Sep 21, 2016
Tracked Since
Feb 18, 2026