CVE-2015-0361: Use After Free
Published Jan 7, 2015
·Updated
Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote domains to cause a denial of service (system crash) via a crafted hypercall during HVM guest teardown.
Affected Software
14 affected components
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.2.3
XEN Xen=4.2.4
XEN Xen=4.2.5
XEN Xen=4.3.0
XEN Xen=4.3.1
XEN Xen=4.3.2
XEN Xen=4.3.3
XEN Xen=4.4.0
XEN Xen=4.4.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Remediation
Patch Available
Event History
Jan 7, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0361?
CVE-2015-0361 has a high severity rating as it allows remote domains to cause a denial of service through crafted hypercalls.
2
How do I fix CVE-2015-0361?
To fix CVE-2015-0361, update your Xen installation to a version that addresses this vulnerability.
3
Which versions of Xen are affected by CVE-2015-0361?
CVE-2015-0361 affects Xen versions 4.2.x, 4.3.x, and 4.4.x.
4
Can CVE-2015-0361 lead to a system crash?
Yes, CVE-2015-0361 can lead to a system crash due to the use-after-free vulnerability during HVM guest teardown.
5
Is CVE-2015-0361 a local or remote vulnerability?
CVE-2015-0361 is a remote vulnerability that can be exploited by an attacker from a remote domain.