CVE-2015-8338

Xen < 4.6.0 - Denial of Service via Memory Operation Suboperations

Title source: llm
STIX 2.1

Description

Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2) XENMEM_populate_physmap, (3) XENMEM_exchange, and possibly other HYPERVISOR_memory_op suboperations, which allows ARM guest OS administrators to cause a denial of service (CPU consumption, guest reboot, or watchdog timeout and host reboot) and possibly have unspecified other impact via unknown vectors.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/78920
Vendor Advisory x_refsource_confirm
http://xenbits.xen.org/xsa/advisory-158.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034390
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3633

Scores

EPSS 0.0020
EPSS Percentile 41.7%

Details

CWE
CWE-254
Status published
Products (1)
xen/xen < 4.6.0
Published Dec 17, 2015
Tracked Since Feb 18, 2026