CVE Vulnerabilities

CVE-2015-7972

Published: Oct 30, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.7 MODERATE
AV:L/AC:M/Au:N/C:N/I:N/A:C
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to heavy memory pressure.

Affected Software

NameVendorStart VersionEnd Version
XenXen3.4.0 (including)3.4.0 (including)
XenXen3.4.1 (including)3.4.1 (including)
XenXen3.4.2 (including)3.4.2 (including)
XenXen3.4.3 (including)3.4.3 (including)
XenXen3.4.4 (including)3.4.4 (including)
XenXen4.0.0 (including)4.0.0 (including)
XenXen4.0.1 (including)4.0.1 (including)
XenXen4.0.2 (including)4.0.2 (including)
XenXen4.0.3 (including)4.0.3 (including)
XenXen4.0.4 (including)4.0.4 (including)
XenXen4.1.0 (including)4.1.0 (including)
XenXen4.1.1 (including)4.1.1 (including)
XenXen4.1.2 (including)4.1.2 (including)
XenXen4.1.3 (including)4.1.3 (including)
XenXen4.1.4 (including)4.1.4 (including)
XenXen4.1.5 (including)4.1.5 (including)
XenXen4.1.6.1 (including)4.1.6.1 (including)
XenXen4.2.0 (including)4.2.0 (including)
XenXen4.2.1 (including)4.2.1 (including)
XenXen4.2.2 (including)4.2.2 (including)
XenXen4.2.3 (including)4.2.3 (including)
XenXen4.3.0 (including)4.3.0 (including)
XenXen4.3.1 (including)4.3.1 (including)
XenXen4.3.2 (including)4.3.2 (including)
XenXen4.3.4 (including)4.3.4 (including)
XenXen4.4.0 (including)4.4.0 (including)
XenXen4.4.1 (including)4.4.1 (including)
XenXen4.5.0 (including)4.5.0 (including)
XenXen4.5.1 (including)4.5.1 (including)
XenXen4.6.0 (including)4.6.0 (including)
XenUbuntudevel*
XenUbuntuprecise*
XenUbuntutrusty*
XenUbuntuvivid*
XenUbuntuwily*

References