SB2016120112 - Incorrect calculation in xen (Alpine package)
Published: December 1, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect calculation (CVE-ID: CVE-2016-9377)
The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
Remediation
Install update from vendor's website.