CVE-2015-7311: Low severity xen xapi vulnerability
Published Oct 1, 2015
·Updated
libxl in Xen 4.1.x through 4.6.x does not properly handle the readonly flag on disks when using the qemu-xen device model, which allows local guest users to write to a read-only disk image.
Affected Software
23 affected components
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.1.6.1
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.2.3
XEN Xen=4.2.4
XEN Xen=4.2.5
XEN Xen=4.3.0
XEN Xen=4.3.1
XEN Xen=4.3.2
XEN Xen=4.3.3
XEN Xen=4.3.4
XEN Xen=4.4.0
XEN Xen=4.4.0-rc1
XEN Xen=4.4.1
XEN Xen=4.5.0
XEN Xen=4.5.1
Event History
Oct 1, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7311?
CVE-2015-7311 has a medium severity rating due to its potential for local attack vectors.
2
How do I fix CVE-2015-7311?
To fix CVE-2015-7311, update to the latest version of Xen that addresses this vulnerability.
3
Who is affected by CVE-2015-7311?
CVE-2015-7311 affects users of Xen versions 4.1.x through 4.6.x using the qemu-xen device model.
4
What are the implications of CVE-2015-7311?
CVE-2015-7311 allows local guest users to write to a read-only disk image, potentially compromising data integrity.
5
Is there a workaround for CVE-2015-7311?
There are no official workarounds for CVE-2015-7311, and users are advised to apply patches as soon as possible.