CVE-2016-3961: Canonical Ubuntu Linux
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 15.10 only; version 16.04 only
- Xen Xen: up to and including 4.5.3
Published 2016-04-15. Last modified 2026-06-17.