~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
Candidate: CVE-2016-9932
PublicDate: 2017-01-26
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9932
 https://xenbits.xen.org/xsa/advisory-200.html
Description:
 CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local
 HVM guest OS users to obtain sensitive information from host stack memory
 via a "supposedly-ignored" operand size prefix.
Ubuntu-Description:
Notes:
 mdeslaur> This is XSA-200
Bugs:
Priority: medium
Discovered-by: Jan Beulich
Assigned-to:

Patches_xen:
Tags_xen: universe-binary
upstream_xen: needs-triage
precise_xen: released (4.1.6.1-0ubuntu0.12.04.13)
precise/esm_xen: DNE (precise was released [4.1.6.1-0ubuntu0.12.04.13])
trusty_xen: released (4.4.2-0ubuntu0.14.04.9)
vivid/ubuntu-core_xen: DNE
vivid/stable-phone-overlay_xen: DNE
xenial_xen: released (4.6.0-1ubuntu4.3)
yakkety_xen: released (4.7.0-0ubuntu2.1)
zesty_xen: released (4.8.0-1ubuntu1)
devel_xen: released (4.8.0-1ubuntu1)