CVE-2015-4104: High severity xen xapi vulnerability
Published Jun 3, 2015
·Updated
Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors.
Affected Software
31 affected components
XEN Xen=3.3.0
XEN Xen=3.3.1
XEN Xen=3.3.2
XEN Xen=3.4.0
XEN Xen=3.4.1
XEN Xen=3.4.2
XEN Xen=3.4.3
XEN Xen=3.4.4
XEN Xen=4.0.0
XEN Xen=4.0.1
XEN Xen=4.0.2
XEN Xen=4.0.3
XEN Xen=4.0.4
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.1.6.1
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.2.3
XEN Xen=4.3.0
XEN Xen=4.3.1
XEN Xen=4.3.2
XEN Xen=4.3.4
XEN Xen=4.4.0
XEN Xen=4.4.1
XEN Xen=4.5.0
Event History
Jun 3, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4104?
CVE-2015-4104 has a severity rating that indicates the potential for denial of service and unexpected host crashes.
2
How do I fix CVE-2015-4104?
To fix CVE-2015-4104, you need to upgrade your Xen environment to a patched version that addresses this vulnerability.
3
What versions are affected by CVE-2015-4104?
CVE-2015-4104 affects Xen versions from 3.3.x through 4.5.x.
4
What type of vulnerability is CVE-2015-4104?
CVE-2015-4104 is a local denial of service vulnerability that affects x86 HVM guest users.
5
Can CVE-2015-4104 be exploited remotely?
CVE-2015-4104 cannot be exploited remotely, as it requires local access to the x86 HVM guest.