CVE-2015-7969: Medium severity xen xapi vulnerability
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XENDOMCTLmaxvcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROFgetbuffer or (3) XENOPROFsetpassive hypercall.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7969?
CVE-2015-7969 has a high severity rating due to its potential to cause denial of service through memory leaks.
How do I fix CVE-2015-7969?
To fix CVE-2015-7969, you should upgrade to the latest stable release of Xen that addresses this vulnerability.
Who is affected by CVE-2015-7969?
CVE-2015-7969 affects local guest administrators or domains with certain permissions in Xen versions 4.0 through 4.6.x.
What are the symptoms of CVE-2015-7969 exploitation?
Exploitation of CVE-2015-7969 can lead to high memory consumption and possible denial of service for virtual machines.
When was CVE-2015-7969 disclosed?
CVE-2015-7969 was disclosed in November 2015.