PT-2015-7768 · Xen+1 · Xen+1
Jan Beulich
·
Published
2015-12-17
·
Updated
2024-06-15
·
CVE-2015-8340
CVSS v2.0
4.7
Medium
| Vector | AV:L/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Xen versions 3.2.x through 4.6.x
Description
The issue is related to the memory exchange function in Xen, which does not properly release locks. This could allow guest OS administrators to cause a denial of service, resulting in a deadlock or host crash, via unspecified vectors. The problem is related to XENMEM exchange error handling.
Recommendations
For Xen versions 3.2.x through 4.6.x, consider applying a patch that fixes the memory exchange function to properly release locks, or temporarily restrict access to the memory exchange function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Xen