CVE-2015-8338: High severity xen xapi vulnerability
Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEMincreasereservation, (2) XENMEMpopulatephysmap, (3) XENMEMexchange, and possibly other HYPERVISORmemoryop suboperations, which allows ARM guest OS administrators to cause a denial of service (CPU consumption, guest reboot, or watchdog timeout and host reboot) and possibly have unspecified other impact via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8338?
CVE-2015-8338 has a high severity rating due to the potential for denial of service attacks.
How do I fix CVE-2015-8338?
To mitigate CVE-2015-8338, upgrade to Xen version 4.6.1 or later where the vulnerability has been addressed.
Which versions of Xen are affected by CVE-2015-8338?
CVE-2015-8338 affects Xen versions up to and including 4.6.0.
What types of attacks are possible due to CVE-2015-8338?
CVE-2015-8338 allows ARM guest OS administrators to conduct denial of service attacks, affecting system stability.
Is CVE-2015-8338 specific to any architecture?
Yes, CVE-2015-8338 specifically impacts ARM architecture in Xen hypervisor environments.