CVE-2015-4163: Null Pointer Dereference
GNTTABOPswapgrantref in Xen 4.2 through 4.5 does not check the grant table operation version, which allows local guest domains to cause a denial of service (NULL pointer dereference) via a hypercall without a GNTTABOPsetuptable or GNTTABOPsetversion.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4163?
CVE-2015-4163 has a medium severity level as it allows local guest domains to cause a denial of service through a NULL pointer dereference.
How do I fix CVE-2015-4163?
To fix CVE-2015-4163, upgrade your Xen software to a version that is not affected, starting from version 4.5.0 and later.
Which versions of Xen are affected by CVE-2015-4163?
CVE-2015-4163 affects Xen versions 4.2.0 through 4.5.0, including versions 4.2.x, 4.3.x, and 4.4.x.
What impact does CVE-2015-4163 have on Xen systems?
CVE-2015-4163 allows for a denial of service attack, leading to potential crashes of guest domains.
Can CVE-2015-4163 be exploited remotely?
CVE-2015-4163 cannot be exploited remotely as it requires local access within the guest domain.