Junglewise Threat Intelligence

CVE-2016-9379: Xen pygrub delimiter injection in S-expression output

CVE-2016-9379 · Severity: high · CVSS 7.9 · Published 2017-01-23

Technologies: Citrix Xenserver, Xen Project Xen. Vendors: Citrix, Xen Project.

Executive brief

Xen is a hypervisor used to run multiple virtual machines on a single physical server. A vulnerability in its pygrub boot loader emulator allows an administrator of a guest virtual machine to trick the host system into reading or deleting files on the physical server. This could lead to the exposure of sensitive host data or a service outage if critical system files are removed.

Technical details

A delimiter injection vulnerability exists in the pygrub boot loader emulator within Xen. When the S-expression output format is requested, pygrub fails to properly quote or validate results reported to the toolstack (libxl, xl, or libvirt). A malicious guest administrator can craft a bootloader configuration file containing specific string quotes and S-expressions to manipulate the toolstack into treating arbitrary host files as the guest's initial ramdisk. This allows the guest to read the contents of those host files or cause the toolstack to delete them during the boot process. The vulnerability affects systems where guests are configured to boot using pygrub (typically PV domains on x86).

Affected products

  • Xen Project Xen 2.0 and later
  • Citrix XenServer 6.0.2, 6.2.0, 6.5, 7.0

Timeline

  • 2016-11-22: disclosed: Initial public release of XSA-198
  • 2016-11-22: patched: Patch released by Xen Project
  • 2017-01-23: advisory: NVD publication date

References

Related threats