← Vulnerability feed

Vulnerability record · CVE-2016-4480 · published 18 May 2016

CVE-2016-4480: Oracle vm server permissions and access controls vulnerability

Oracle · Vm Server

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

8.4 CVSS 3.0 High EPSS 0.54% · top 56.7% CWE-264 · Permissions and access controls
8.4CVSS 3.0 base score, v2 7.2
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-4480 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2017-10912Xen vulnerabilityXen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.EPSS 2.7%10.0CVE-2017-10918Xen improper input validation vulnerabilityXen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access…EPSS 3.7%10.0CVE-2017-10920Xen memory buffer overflow vulnerabilityThe grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unma…EPSS 2.5%10.0CVE-2017-10921Xen memory buffer overflow vulnerabilityThe grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows…EPSS 2.5%10.0CVE-2015-8104Xen vulnerabilityThe KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic o…EPSS 2.5%9.9CVE-2017-2620Qemu out-of-bounds write vulnerabilityQuick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could…EPSS 3.6%9.9CVE-2018-12892Debian linux information exposure vulnerabilityAn issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probabl…EPSS 2.5%9.8CVE-2025-58142Xen vulnerability[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple i…EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2016-4480), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.