CVE-2015-8341: High severity xen xapi vulnerability
The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8341?
CVE-2015-8341 has a moderate severity level as it can lead to denial of service through memory and disk consumption.
How do I fix CVE-2015-8341?
To fix CVE-2015-8341, upgrade to a version of Xen beyond 4.6.x that includes the relevant patches.
What impact does CVE-2015-8341 have on affected systems?
CVE-2015-8341 can cause denial of service by allowing attackers to start multiple domains, leading to resource depletion.
Which versions of Xen are affected by CVE-2015-8341?
CVE-2015-8341 affects Xen versions from 4.1.0 through 4.6.0.
Is there a workaround for CVE-2015-8341?
A temporary workaround for CVE-2015-8341 is to limit the number of domains that can be started in the affected Xen environment.