The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges by manipulating information in guest controlled areas of xenstore.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html | vendor advisory |
http://xenbits.xen.org/xsa/advisory-175.html | vendor advisory |
http://www.securityfocus.com/bid/91006 | vdb entry |
http://www.debian.org/security/2016/dsa-3633 | vendor advisory |
http://www.securitytracker.com/id/1036023 | vdb entry third party advisory |