CVE-2015-7972: Low severity xen xapi vulnerability
The (1) libxlsetmemorytarget function in tools/libxl/libxl.c and (2) libxlbuildpost function in tools/libxl/libxldom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pressure."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7972?
CVE-2015-7972 has a severity rating that indicates a potential denial of service vulnerability in Xen.
How do I fix CVE-2015-7972?
To fix CVE-2015-7972, ensure your Xen installation is updated to a version that includes the official patches.
What versions of Xen are affected by CVE-2015-7972?
CVE-2015-7972 affects Xen versions from 3.4.x through 4.6.x, including specific versions noted in the CVE.
What type of attack does CVE-2015-7972 facilitate?
CVE-2015-7972 facilitates a denial of service attack by allowing local HVM guest users to manipulate memory allocation.
Is there a workaround for CVE-2015-7972?
There are no specific workarounds for CVE-2015-7972, so upgrading to a patched version is recommended.