CVE-2015-7835: Input Validation
Published Oct 30, 2015
·Updated
The modl2entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV guest administrators to gain privileges via a crafted superpage mapping.
Affected Software
30 affected components
XEN Xen=3.4.0
XEN Xen=3.4.1
XEN Xen=3.4.2
XEN Xen=3.4.3
XEN Xen=3.4.4
XEN Xen=4.0.0
XEN Xen=4.0.1
XEN Xen=4.0.2
XEN Xen=4.0.3
XEN Xen=4.0.4
XEN Xen=4.1.0
XEN Xen=4.1.1
XEN Xen=4.1.2
XEN Xen=4.1.3
XEN Xen=4.1.4
XEN Xen=4.1.5
XEN Xen=4.1.6.1
XEN Xen=4.2.0
XEN Xen=4.2.1
XEN Xen=4.2.2
XEN Xen=4.2.3
XEN Xen=4.3.0
XEN Xen=4.3.1
XEN Xen=4.3.2
XEN Xen=4.3.4
XEN Xen=4.4.0
XEN Xen=4.4.1
XEN Xen=4.5.0
XEN Xen=4.5.1
XEN Xen=4.6.0
Event History
Oct 30, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7835?
CVE-2015-7835 is considered a medium severity vulnerability due to the potential privilege escalation it allows.
2
How do I fix CVE-2015-7835?
To fix CVE-2015-7835, you should upgrade to a patched version of Xen that addresses the flaw.
3
Who is affected by CVE-2015-7835?
CVE-2015-7835 affects local PV guest administrators using vulnerable versions of Xen 3.4 through 4.6.x.
4
What type of vulnerability is CVE-2015-7835?
CVE-2015-7835 is a privilege escalation vulnerability resulting from improper validation of level 2 page table entries.
5
When was CVE-2015-7835 disclosed?
CVE-2015-7835 was disclosed in November 2015, highlighting security risks in several versions of Xen.