First published: Thu Dec 17 2015(Updated: )
The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xen xen-unstable | =4.1.0 | |
Xen xen-unstable | =4.1.1 | |
Xen xen-unstable | =4.1.2 | |
Xen xen-unstable | =4.1.3 | |
Xen xen-unstable | =4.1.4 | |
Xen xen-unstable | =4.1.5 | |
Xen xen-unstable | =4.1.6 | |
Xen xen-unstable | =4.1.6.1 | |
Xen xen-unstable | =4.2.0 | |
Xen xen-unstable | =4.2.1 | |
Xen xen-unstable | =4.2.2 | |
Xen xen-unstable | =4.2.3 | |
Xen xen-unstable | =4.2.4 | |
Xen xen-unstable | =4.2.5 | |
Xen xen-unstable | =4.3.0 | |
Xen xen-unstable | =4.3.1 | |
Xen xen-unstable | =4.3.2 | |
Xen xen-unstable | =4.3.3 | |
Xen xen-unstable | =4.3.4 | |
Xen xen-unstable | =4.4.0 | |
Xen xen-unstable | =4.4.1 | |
Xen xen-unstable | =4.4.2 | |
Xen xen-unstable | =4.4.3 | |
Xen xen-unstable | =4.5.0 | |
Xen xen-unstable | =4.5.1 | |
Xen xen-unstable | =4.5.2 | |
Xen xen-unstable | =4.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8341 has a moderate severity level as it can lead to denial of service through memory and disk consumption.
To fix CVE-2015-8341, upgrade to a version of Xen beyond 4.6.x that includes the relevant patches.
CVE-2015-8341 can cause denial of service by allowing attackers to start multiple domains, leading to resource depletion.
CVE-2015-8341 affects Xen versions from 4.1.0 through 4.6.0.
A temporary workaround for CVE-2015-8341 is to limit the number of domains that can be started in the affected Xen environment.