Lucene search

K
cveMitreCVE-2015-7972
HistoryOct 30, 2015 - 3:59 p.m.

CVE-2015-7972

2015-10-3015:59:09
CWE-399
mitre
web.nvd.nist.gov
53
xen
cve-2015-7972
denial of service
vulnerability
security
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

26.7%

The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to “heavy memory pressure.”

Affected configurations

Nvd
Node
xenxenMatch3.4.0
OR
xenxenMatch3.4.1
OR
xenxenMatch3.4.2
OR
xenxenMatch3.4.3
OR
xenxenMatch3.4.4
OR
xenxenMatch4.0.0
OR
xenxenMatch4.0.1
OR
xenxenMatch4.0.2
OR
xenxenMatch4.0.3
OR
xenxenMatch4.0.4
OR
xenxenMatch4.1.0
OR
xenxenMatch4.1.1
OR
xenxenMatch4.1.2
OR
xenxenMatch4.1.3
OR
xenxenMatch4.1.4
OR
xenxenMatch4.1.5
OR
xenxenMatch4.1.6.1
OR
xenxenMatch4.2.0
OR
xenxenMatch4.2.1
OR
xenxenMatch4.2.2
OR
xenxenMatch4.2.3
OR
xenxenMatch4.3.0
OR
xenxenMatch4.3.1
OR
xenxenMatch4.3.2
OR
xenxenMatch4.3.4
OR
xenxenMatch4.4.0
OR
xenxenMatch4.4.1-
OR
xenxenMatch4.5.0
OR
xenxenMatch4.5.1
OR
xenxenMatch4.6.0
VendorProductVersionCPE
xenxen3.4.0cpe:2.3:o:xen:xen:3.4.0:*:*:*:*:*:*:*
xenxen3.4.1cpe:2.3:o:xen:xen:3.4.1:*:*:*:*:*:*:*
xenxen3.4.2cpe:2.3:o:xen:xen:3.4.2:*:*:*:*:*:*:*
xenxen3.4.3cpe:2.3:o:xen:xen:3.4.3:*:*:*:*:*:*:*
xenxen3.4.4cpe:2.3:o:xen:xen:3.4.4:*:*:*:*:*:*:*
xenxen4.0.0cpe:2.3:o:xen:xen:4.0.0:*:*:*:*:*:*:*
xenxen4.0.1cpe:2.3:o:xen:xen:4.0.1:*:*:*:*:*:*:*
xenxen4.0.2cpe:2.3:o:xen:xen:4.0.2:*:*:*:*:*:*:*
xenxen4.0.3cpe:2.3:o:xen:xen:4.0.3:*:*:*:*:*:*:*
xenxen4.0.4cpe:2.3:o:xen:xen:4.0.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 301

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

26.7%