CVE-2015-8338
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 17 Dec 2015, 19:00
Last modified:06 Aug 2024, 08:13
Vulnerability Summary
Overall Risk (default)
medium
29/100 CVSS Score
7.2 HIGH
v2.0 (nvd)
EPSS Score
0.2% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
17 Dec 2015, 19:00
Published
Vulnerability first disclosed
06 Aug 2024, 08:13
Last Modified
Vulnerability information updated
Description
Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2) XENMEM_populate_physmap, (3) XENMEM_exchange, and possibly other HYPERVISOR_memory_op suboperations, which allows ARM guest OS administrators to cause a denial of service (CPU consumption, guest reboot, or watchdog timeout and host reboot) and possibly have unspecified other impact via unknown vectors.
CVSS Metrics
- v2.0•HIGH•Score: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.20%• Percentile: 42%
Techniques & Countermeasures
- CWE-254•7PK - Security Features
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Affected Systems
- xen•xen
≤ 4.6.0