CVE Vulnerabilities

CVE-2015-7969

Published: Oct 30, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of teardowns of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.

Affected Software

NameVendorStart VersionEnd Version
XenXen4.0.0 (including)4.0.0 (including)
XenXen4.0.1 (including)4.0.1 (including)
XenXen4.0.2 (including)4.0.2 (including)
XenXen4.0.3 (including)4.0.3 (including)
XenXen4.0.4 (including)4.0.4 (including)
XenXen4.1.0 (including)4.1.0 (including)
XenXen4.1.1 (including)4.1.1 (including)
XenXen4.1.2 (including)4.1.2 (including)
XenXen4.1.3 (including)4.1.3 (including)
XenXen4.1.4 (including)4.1.4 (including)
XenXen4.1.5 (including)4.1.5 (including)
XenXen4.1.6.1 (including)4.1.6.1 (including)
XenXen4.2.0 (including)4.2.0 (including)
XenXen4.2.1 (including)4.2.1 (including)
XenXen4.2.2 (including)4.2.2 (including)
XenXen4.2.3 (including)4.2.3 (including)
XenXen4.3.0 (including)4.3.0 (including)
XenXen4.3.1 (including)4.3.1 (including)
XenXen4.3.2 (including)4.3.2 (including)
XenXen4.3.4 (including)4.3.4 (including)
XenXen4.4.0 (including)4.4.0 (including)
XenXen4.4.1 (including)4.4.1 (including)
XenXen4.5.0 (including)4.5.0 (including)
XenXen4.5.1 (including)4.5.1 (including)
XenXen4.6.0 (including)4.6.0 (including)
XenUbuntudevel*
XenUbuntuprecise*
XenUbuntutrusty*
XenUbuntuvivid*
XenUbuntuwily*

References