CVE-2016-9386
UnknownEPSS 0.45%
Last modified
CVE-2016-9386 is a vulnerability of currently unknown severity. The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Citrix | Xenserver | 6.0.2 |
| Citrix | Xenserver | 6.2.0 |
| Citrix | Xenserver | 6.5 |
| Citrix | Xenserver | 7.0 |
| Xen | Xen | All versions |
References
- http://www.securityfocus.com/bid/94471Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037340Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-191.htmlPatch, Vendor Advisory
- https://support.citrix.com/article/CTX218775Patch, Third Party Advisory
- http://www.securityfocus.com/bid/94471Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037340Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-191.htmlPatch, Vendor Advisory
- https://support.citrix.com/article/CTX218775Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-9386?
The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.
How severe is CVE-2016-9386?
Severity scoring for CVE-2016-9386 is pending analysis. The EPSS model estimates a 0.45% probability of exploitation in the next 30 days.
How do I fix CVE-2016-9386?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-9380The pygrub boot loader emulator in Xen, when nul-delimited o…
- CVE-2016-9381Race condition in QEMU in Xen allows local x86 HVM guest OS …7.5
- CVE-2016-9382Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 …
- CVE-2016-9383Xen, when running on a 64-bit hypervisor, allows local x86 g…
- CVE-2016-9384Xen 4.7 allows local guest OS users to obtain sensitive host…
- CVE-2016-9385The x86 segment base write emulation functionality in Xen 4.…
- CVE-2016-9387Integer overflow in the jpc_dec_process_siz function in libj…
- CVE-2016-9388The ras_getcmap function in ras_dec.c in JasPer before 1.900…5.5
- CVE-2016-9389The jpc_irct and jpc_iict functions in jpc_mct.c in JasPer b…
- CVE-2016-9390The jas_seq2d_create function in jas_seq.c in JasPer before …
- CVE-2016-9391The jpc_bitstream_getbits function in jpc_bs.c in JasPer bef…
- CVE-2016-9392The calcstepsizes function in jpc_dec.c in JasPer before 1.9…
Are you affected by CVE-2016-9386?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
