Executive brief
Xen is a hypervisor used to run multiple virtual machines on a single physical server. A vulnerability in how it handles certain processor instructions allows an administrator of a guest virtual machine to crash the entire physical host. This results in a total service outage for all other virtual machines running on that same hardware.
Technical details
A vulnerability exists in Xen's emulation of x86 segment base writes, specifically affecting the FS and GS register base MSRs and the WRFSBASE/WRGSBASE instructions. These instructions require input values to be in canonical form; otherwise, a general protection fault (#GP) is triggered. The hypervisor's recovery code for these faults was inadvertently removed when support for these instructions was enabled. A malicious administrator of a Paravirtualized (PV) guest can provide non-canonical addresses to trigger an unhandled #GP fault, leading to a hypervisor crash and host-wide denial of service. HVM guests are not affected. Patches are available from the Xen Project (XSA-193).
Affected products
- Xen Project Xen 4.4.x through 4.7.x
- Citrix XenServer 6.0.2, 6.2.0, 6.5, 7.0
Timeline
- 2016-11-22: advisory: XSA-193 public release
- 2016-11-22: patched: Patches released for Xen unstable, 4.7.x, 4.6.x, 4.5.x, and 4.4.x
- 2017-01-23: disclosed: NVD publication date