SB2016122012 - Information disclosure in xen (Alpine package)
Published: December 20, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2016-9932)
The vulnerability allows a local authenticated user to gain access to sensitive information.
CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=e719edc6313651540e9d90f5600c2ed605fa6abf
- https://git.alpinelinux.org/aports/commit/?id=606dbad6dd155ec3aebfba4513206d9bdea93b52
- https://git.alpinelinux.org/aports/commit/?id=429e21cec4a19bb630e26ace13a7e81c4d8bc5dd
- https://git.alpinelinux.org/aports/commit/?id=bb51c7f4170f84a98bc3789732d7c06ab575323f
- https://git.alpinelinux.org/aports/commit/?id=cd39a7408c7e39b480eef2647ee7757bb1be4df5