CVE-2015-8338
Xen < 4.6.0 - Denial of Service via Memory Operation Suboperations
Title source: llmDescription
Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2) XENMEM_populate_physmap, (3) XENMEM_exchange, and possibly other HYPERVISOR_memory_op suboperations, which allows ARM guest OS administrators to cause a denial of service (CPU consumption, guest reboot, or watchdog timeout and host reboot) and possibly have unspecified other impact via unknown vectors.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/78920
Vendor Advisory x_refsource_confirm
http://xenbits.xen.org/xsa/advisory-158.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1034390
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2016/dsa-3633
Scores
EPSS
0.0020
EPSS Percentile
41.7%
Details
CWE
CWE-254
Status
published
Products (1)
xen/xen
< 4.6.0
Published
Dec 17, 2015
Tracked Since
Feb 18, 2026