CVE-2015-7812: Medium severity xen xapi vulnerability
Published Nov 17, 2015
·Updated
The hypercallcreatecontinuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.
Affected Software
8 affected components
XEN Xen=4.4.0
XEN Xen=4.4.1
XEN Xen=4.4.2
XEN Xen=4.4.3
XEN Xen=4.5.0
XEN Xen=4.5.1
XEN Xen=4.5.2
XEN Xen=4.6.0
Remediation
Patch Available
Event History
Nov 17, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7812?
CVE-2015-7812 is classified as a denial of service vulnerability that can lead to a host crash.
2
How do I fix CVE-2015-7812?
To fix CVE-2015-7812, update your Xen hypervisor to version 4.6.x or later.
3
Which versions of Xen are affected by CVE-2015-7812?
Xen versions 4.4.x through 4.6.x are affected by CVE-2015-7812.
4
Can CVE-2015-7812 be exploited by local users?
Yes, CVE-2015-7812 can be exploited by local guest users through a preemptible hypercall.
5
What impact does CVE-2015-7812 have on system stability?
CVE-2015-7812 can cause a denial of service, resulting in instability or crash of the host system.