CVE Vulnerabilities

CVE-2015-8338

Published: Dec 17, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.3 IMPORTANT
AV:N/AC:M/Au:S/C:N/I:N/A:C
RedHat/V3
6.2 IMPORTANT
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2) XENMEM_populate_physmap, (3) XENMEM_exchange, and possibly other HYPERVISOR_memory_op suboperations, which allows ARM guest OS administrators to cause a denial of service (CPU consumption, guest reboot, or watchdog timeout and host reboot) and possibly have unspecified other impact via unknown vectors.

Affected Software

NameVendorStart VersionEnd Version
XenXen*4.6.0 (including)
XenUbuntudevel*
XenUbuntutrusty*
XenUbuntuupstream*
XenUbuntuvivid*
XenUbuntuwily*

References