PT-2016-3927 · Xen+1 · Xen+1

Jan Beulich

·

Published

2016-01-14

·

Updated

2024-06-15

·

CVE-2015-8555

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen versions 4.6.x through 4.3.x and earlier
Description The issue allows local guest domains to obtain sensitive information from other domains via unspecified vectors due to the lack of initialization of x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state.
Recommendations For Xen versions 4.6.x through 4.3.x and earlier, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8555
DLA-479-1
DSA-3519-1
MGASA-2016-0098
OPENSUSE-SU-2016_0123-1
OPENSUSE-SU-2016_0124-1
OPENSUSE-SU-2016_0126-1
OPENSUSE-SU-2024:10196-1
SUSE-SU-2016:0873-1
SUSE-SU-2016:0955-1
SUSE-SU-2016:1154-1
SUSE-SU-2016:1318-1
SUSE-SU-2016:1745-1

Affected Products

Suse
Xen