CVE-2016-7092: Xen

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables.

Affected products

  • Xen Xen: affected versions not specified

Published 2016-09-21. Last modified 2026-06-17.