CVE-2015-7971: Low severity xen xapi vulnerability
Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of service via a sequence of crafted (1) HYPERCALLxenoprofop hypercalls, which are not properly handled in the doxenoprofop function in common/xenoprof.c, or (2) HYPERVISORxenpmuop hypercalls, which are not properly handled in the doxenpmuop function in arch/x86/cpu/vpmu.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7971?
CVE-2015-7971 is classified as a denial of service vulnerability due to its ability to flood the console with excessive messages.
How do I fix CVE-2015-7971?
To fix CVE-2015-7971, upgrade to a patched version of Xen that addresses this vulnerability.
Which versions of Xen are affected by CVE-2015-7971?
Xen versions 3.2.x through 4.6.x are affected by CVE-2015-7971.
What can attackers do with CVE-2015-7971?
Attackers can exploit CVE-2015-7971 to create a denial of service condition on affected Xen instances through crafted hypercalls.
Is CVE-2015-7971 a remote attack vector?
CVE-2015-7971 is a local vulnerabilities that require an attacker to have access to the guest operating system.