CVE Vulnerabilities

CVE-2015-8341

Published: Dec 17, 2015 | Modified: Jul 01, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
4.9 MODERATE
AV:N/AC:H/Au:S/C:N/I:N/A:C
RedHat/V3
Ubuntu
MEDIUM

The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.

Affected Software

Name Vendor Start Version End Version
Xen Xen 4.1.0 (including) 4.1.0 (including)
Xen Xen 4.1.1 (including) 4.1.1 (including)
Xen Xen 4.1.2 (including) 4.1.2 (including)
Xen Xen 4.1.3 (including) 4.1.3 (including)
Xen Xen 4.1.4 (including) 4.1.4 (including)
Xen Xen 4.1.5 (including) 4.1.5 (including)
Xen Xen 4.1.6 (including) 4.1.6 (including)
Xen Xen 4.1.6.1 (including) 4.1.6.1 (including)
Xen Xen 4.2.0 (including) 4.2.0 (including)
Xen Xen 4.2.1 (including) 4.2.1 (including)
Xen Xen 4.2.2 (including) 4.2.2 (including)
Xen Xen 4.2.3 (including) 4.2.3 (including)
Xen Xen 4.2.4 (including) 4.2.4 (including)
Xen Xen 4.2.5 (including) 4.2.5 (including)
Xen Xen 4.3.0 (including) 4.3.0 (including)
Xen Xen 4.3.1 (including) 4.3.1 (including)
Xen Xen 4.3.2 (including) 4.3.2 (including)
Xen Xen 4.3.3 (including) 4.3.3 (including)
Xen Xen 4.3.4 (including) 4.3.4 (including)
Xen Xen 4.4.0 (including) 4.4.0 (including)
Xen Xen 4.4.1 (including) 4.4.1 (including)
Xen Xen 4.4.2 (including) 4.4.2 (including)
Xen Xen 4.4.3 (including) 4.4.3 (including)
Xen Xen 4.5.0 (including) 4.5.0 (including)
Xen Xen 4.5.1 (including) 4.5.1 (including)
Xen Xen 4.5.2 (including) 4.5.2 (including)
Xen Xen 4.6.0 (including) 4.6.0 (including)
Xen Ubuntu devel *
Xen Ubuntu trusty *
Xen Ubuntu upstream *
Xen Ubuntu vivid *
Xen Ubuntu wily *

References