CVE-2016-3157
Last modified
CVE-2016-3157 is a vulnerability of currently unknown severity. The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause a denial of service (guest OS crash), or obtain sensitive information by leveraging I/O port access.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause a denial of service (guest OS crash), or obtain sensitive information by leveraging I/O port access.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | 4.0.0 |
| Canonical | Ubuntu Linux | 12.04 |
References
- http://xenbits.xen.org/xsa/advisory-171.htmlPatch, Vendor Advisory
- http://xenbits.xen.org/xsa/advisory-171.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-3157?
How severe is CVE-2016-3157?
How do I fix CVE-2016-3157?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-3151Directory traversal vulnerability in the wallpaper parsing f…
- CVE-2016-3152Barco ClickShare CSC-1 devices with firmware before 01.09.03…
- CVE-2016-3153SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x befor…
- CVE-2016-3154The encoder_contexte_ajax function in ecrire/inc/filtres.php…
- CVE-2016-3155Siemens APOGEE Insight uses weak permissions for the applica…
- CVE-2016-3156The IPv4 implementation in the Linux kernel before 4.5.2 mis…
- CVE-2016-3158The xrstor function in arch/x86/xstate.c in Xen 4.x does not…
- CVE-2016-3159The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does …
- CVE-2016-3161For the NVIDIA Quadro, NVS, and GeForce products, GFE GameSt…
- CVE-2016-3162The File module in Drupal 7.x before 7.43 and 8.x before 8.0…
- CVE-2016-3163The XML-RPC system in Drupal 6.x before 6.38 and 7.x before …
- CVE-2016-3164Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.…
Are you affected by CVE-2016-3157?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
