PT-2015-2192 · Xen+1 · Qemu-Xen+3

Lin Liu

·

Published

2015-10-01

·

Updated

2024-06-15

·

CVE-2015-7311

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xen versions 4.1.x through 4.6.x
Description The issue arises from the libxl library in Xen not properly handling the readonly flag on disks when using the qemu-xen device model. This allows local guest users to write to a read-only disk image, potentially leading to unauthorized data modification. The vulnerability is due to the lack of restrictions on writing when using qemu-xen devices, enabling a local attacker to write data to a disk intended for read-only access.
Recommendations For Xen versions 4.1.x through 4.6.x, consider restricting access to the qemu-xen device model until a patch is available to properly enforce the readonly flag on disks. As a temporary workaround, limiting the use of read-only disk images with the qemu-xen device model can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11538
CVE-2015-7311
DSA-3414-1
MGASA-2016-0098
OPENSUSE-SU-2015_1964-1
OPENSUSE-SU-2015_2003-1
OPENSUSE-SU-2016_0124-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2015:1853-1
SUSE-SU-2015:1894-1
SUSE-SU-2015:1908-1
SUSE-SU-2015:2324-1
SUSE-SU-2015:2326-1
SUSE-SU-2015:2328-1
SUSE-SU-2015:2338-1

Affected Products

Suse
Xen
Libxl
Qemu-Xen