The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.Referenceshttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://xenbits.xen.org/xsa/advisory-182.htmlhttp://xenbits.xen.org/xsa/xsa182-4.6.patchhttp://support.citrix.com/article/CTX214954https://security.gentoo.org/glsa/201611-09http://xenbits.xen.org/xsa/xsa182-unstable.patchhttp://xenbits.xen.org/xsa/xsa182-4.5.patchhttp://www.debian.org/security/2016/dsa-3633http://www.securitytracker.com/id/1036446http://www.securityfocus.com/bid/92131