Lucene search

K
cveMitreCVE-2015-8338
HistoryDec 17, 2015 - 7:59 p.m.

CVE-2015-8338

2015-12-1719:59:06
CWE-254
mitre
web.nvd.nist.gov
46
xen
cve-2015-8338
security
denial of service
vulnerability
arm
hypervisor
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

25.1%

Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2) XENMEM_populate_physmap, (3) XENMEM_exchange, and possibly other HYPERVISOR_memory_op suboperations, which allows ARM guest OS administrators to cause a denial of service (CPU consumption, guest reboot, or watchdog timeout and host reboot) and possibly have unspecified other impact via unknown vectors.

Affected configurations

Nvd
Node
xenxenRange4.6.0
VendorProductVersionCPE
xenxen*cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

25.1%